漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability
Vulnerability Description
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the parsing of AIP files. By creating a symbolic link, an attacker can abuse the installer process to write arbitrary files. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-30583.
CVSS Information
N/A
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
PAX Technology Q80 后置链接漏洞
Vulnerability Description
PAX Technology Q80是中国PAX Technology公司的一款物联网设备。 PAX Technology Q80 2.6.33.6690R版本存在后置链接漏洞,该漏洞源于AIP文件解析过程中存在链接跟随问题,攻击者可通过创建符号链接滥用安装程序进程写入任意文件,进而结合其他漏洞以root权限执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A