$ nmap -p- --min-rate 3000 -Pn 192.168.157.67
Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-16 10:40 +08
Nmap scan report for 192.168.157.67
Host is up (0.17s latency).
Not shown: 65530 filtered tcp ports (no-response)
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh
2222/tcp open EtherNetIP-1
3000/tcp open ppp
FTP does not allow for anonymous logins.
Web Enum -> Gitea RCE
Only port 3000 has a webpage:
In the bottom left, we can see the version, which is vulnerable to RCE: