ISPConfig Admin Default Login Scanner
Targets the ISPConfig Admin login endpoint to identify default username/password combinations, enabling full control panel takeover.
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
1 minute
Time Interval
18 days 15 hours
Scan only one
Domain, IPv4, Subdomain
Toolbox
ISPConfig Admin is a widely used open-source web hosting control panel that allows administrators to manage websites, email accounts, DNS zones, and databases from a single interface. It is commonly deployed by hosting providers, IT professionals, and businesses to streamline server management tasks. The panel's popularity stems from its flexibility and comprehensive feature set, making it a critical component in many hosting environments.
A default login vulnerability occurs when the ISPConfig Admin panel retains factory-set credentials, such as 'admin'/'admin' or 'root'/'password'. This arises from administrators failing to change these defaults during installation or after system updates. Attackers exploit this by attempting common credential pairs against the login endpoint, gaining immediate administrative access without needing to bypass authentication mechanisms.
The vulnerability specifically targets the /admin/index.php endpoint, where the login form accepts username and password parameters. Automated scanners can rapidly test default credential lists against this endpoint, leveraging the lack of rate limiting or account lockout policies. Successful authentication grants full control over the ISPConfig Admin interface, including user management, server configuration, and service control.
If exploited, an attacker can modify hosting accounts, inject malicious code into websites, exfiltrate sensitive data, or disrupt server operations. This can lead to widespread compromise of hosted sites, financial loss, and reputational damage. The high CVSS score of 8.0 reflects the severe impact and ease of exploitation, emphasizing the need for immediate remediation.