天融信等厂商上网行为管理设备任意命令执行漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

两处任意命令执行无需登录: 第一处: ``` if(key_exists("text_target", $_GET) && key_exists("text_pingcount", $_GET) && key_exists("text_packetsize", $_GET)) { $text_target = $_GET["text_target"]; $text_pingcount = $_GET["text_pingcount"]; $text_packetsize = $_GET["text_packetsize"]; $pingcmd = sprintf("ping %s -c %s -s %s", $text_target, $text_pingcount, $text_packetsize); exec($pingcmd, $lines); ``` /view/systemConfig/systemTool/ping/ping.php 第二处: ``` $text_target = $_GET["text_target"]; $text_ageout = $_GET["text_ageout"]; $text_minttl = $_GET["text_minttl"]; $text_maxttl = $_GET["text_maxttl"]; $traceroutecmd = sprintf("traceroute %s -f %s -m %s -w %s -q 1", $text_target, $text_minttl, $text_maxttl, $text_ageout); exec($traceroutecmd, $lines); $rettraceroutecmd .= _gettext("testing_wait").chr(10).chr(10); ``` /view/systemConfig/systemTool/traceRoute/traceroute.php 利用方式同上。 两处命令执行需登录: 第一处:/view/IPV6/ipv6networktool/ping/ping.php ``` if(key_exists("text_target", $_GET) &&...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息