EDIMAX CommandInjection
Command Injection
BR-6428nS V3 Firmware
Firmware Version: BR6428NSv3_1.20
You can download Firmware at this website and use FirmAE to simulate the router environment.
Description
There is a command injection in formWlanMP
Function of binary file webs.
After obtaining the POST parameter, it is directly incorporated into the system function for execution without checking and filtering
PS
You must pass basic verification before you can exploit this vulnerability
can find the user/passwd in website
POC
1 | POST /goform/formWlanMP HTTP/1.1 |
本博客所有文章除特别声明外,均采用 CC BY-NC-SA 4.0 许可协议。转载请注明来自 Swe3ty's blog!