CVE-2021-40903 Information

Description

A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string which would be randomly generated however it is static.

Reference

https://github.com/anselal/antminer-monitor https://www.exploit-db.com/exploits/50267 https://packetstormsecurity.com/files/164048/Antminer-Monitor-0.5.0-Authentication-Bypass.html

Share on: