Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard
Vulnerability Description
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing any network-reachable attacker who knows the defaults to authenticate to the C2 dashboard with operator-level access. This issue is fixed in 0.2.154.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-1392
Vulnerability Title
Grisuno LazyOwn 信任管理问题漏洞
Vulnerability Description
Grisuno LazyOwn是Grisuno个人开发者的一款黑客工具。 Grisuno LazyOwn 0.2.154之前版本存在信任管理问题漏洞,该漏洞源于默认C2凭据LazyOwn和LazyOwn被硬编码在payload.json和core/payload_schema.py中,并传递给lazyc2.py HTTP Basic认证,可能导致任何知道默认凭据的网络可达攻击者以操作员级别访问C2仪表板。
CVSS Information
N/A
Vulnerability Type
N/A