Vulnerable Systems:
* Legrand-003598 and Bticino-F454
Successful exploits will allow unauthenticated attackers to obtain sensitive information from the device, which may facilitate a complete compromise of the system.
VULNERABILITY DESCRIPTION
The file:
https://[ip address of device]/TiWeb.xml
is directly accessible without requiring credential requests of any sort, and contains plaintext login and passwords to the device. These credentials are all that's needed to reprogram the entire home automation system, access video cameras in the installation, control the burglar alarm, and more.
PROOF-OF-CONCEPT/EXPLOIT
just head to the url on an affected device. you can find those devices by searching google for 'top_right_bticino' (and probably 'top_right_legrand')