Bluehood 会监控本地的蓝牙活动。在 0.7.1 版本之前,当启用 auth_enabled(启用认证)时,只有 HTML 页面处理器会执行会话验证。而所有 /api/* 路径的处理程序(包括设置、设备、组以及每个设备的专属端点如 /api/device/{mac}/notes 等)均未进行任何身份认证检查。处于同一网络、且能访问管理界面端口的攻击者,可以在不提供会话 Cookie 的情况下,读取蓝牙追踪数据并修改应用程序状态,包括心跳 URL、数据保留期限、设备分组以及每个设备的专属备注。该漏洞已在 0.7
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet