xsspresso
xsspresso
Tags/ SNMP

SNMP

2 writeups tagged with SNMP

WebMediumLinux

HTB — Monitored

Nagios XI SNMP credential leak, auth bypass CVE-2023-40931 for API key theft. SQL injection creates admin account for RCE via malicious script.

#Nagios#SNMP#SQLi
Jan 19, 2025HackTheBox
MiscMediumLinux

HTB — Mentor

SNMP v3 credential brute-force yields API secret. Command injection in backup API endpoint. PostgreSQL password enables lateral movement and sudo root.

#SNMP#Command Injection#API
Jan 15, 2025HackTheBox