S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-40661 Scanner

CVE-2021-40661 scanner - Directory Traversal vulnerability in IND780 Advanced Weighing Terminals

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
5.3k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-40661
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

A remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Advanced Weighing Terminals Build 8.0.07 March 19, 2018 (SS Label 'IND780_8.0.07'), Version 7.2.10 June 18, 2012 (SS Label 'IND780_7.2.10'). It was possible to traverse the folders of the affected host by providing a traversal path to the 'webpage' parameter in AutoCE.ini This could allow a remote unauthenticated adversary to access additional files on the affected system. This could also allow the adversary to perform further enumeration against the affected host to identify the versions of the systems in use, in order to launch further attacks in future.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The IND780 Advanced Weighing Terminals are a type of industrial weighing scale that is used in various industries such as agriculture, manufacturing, and logistics. These terminals are designed to provide accurate and reliable weight measurements for large, heavy objects such as boxes, pallets, and containers. The IND780 is equipped with a web interface that allows users to monitor and control the weighing process remotely.

Recently, a critical vulnerability was identified in the IND780 Advanced Weighing Terminals, labeled as CVE-2021-40661. This vulnerability is a remote, unauthenticated, directory traversal flaw that can be exploited using the 'webpage' parameter in AutoCE.ini. Attackers can use this vulnerability to access files stored on the affected system, giving them the ability to perform further reconnaissance and potentially launch more sophisticated attacks against the targeted infrastructure.

Exploitation of this vulnerability can lead to serious consequences, including data theft, system compromise, and loss of confidentiality. Attackers can leverage the information obtained from the directory traversal to identify weak points and vulnerabilities within the system, which they can exploit to gain access to sensitive data or disrupt business operations. This is a significant risk for industries that rely on the IND780 terminals for critical operations.

In conclusion, vulnerabilities like CVE-2021-40661 pose a serious threat to the security and reliability of industrial systems like IND780 Advanced Weighing Terminals. By taking the necessary precautions, users can prevent their systems from falling victim to cyber-attacks. With the help of pro features offered by the s4e.io platform, users can stay informed about the latest vulnerabilities and secure their digital assets quickly and easily.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Apply the latest security patches and updates for the IND780 terminals as soon as they become available.
  • Monitor network traffic for any suspicious activity and block incoming requests from unknown sources.
  • Disable unnecessary services on the terminal to reduce the attack surface.
  • Implement access controls such as firewalls, network segmentation to restrict access to the terminal.
  • Perform regular security assessments and penetration testing to identify vulnerabilities before attackers do.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-40661 scanner - Directory Traversal vulnerability in IND780 Advanced Weighing Terminals | S4E