cg33 CC-Connect是cg33个人开发者的一款网络连接设备。 cg33 CC-Connect 1.4.1及之前版本存在安全漏洞,该漏洞源于对文件core/webhook.go中Authenticate函数参数exec的错误操作,可能导致代码注入。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| chenhg5 | cc-connect | 1.4.0 |
affected |
1.4.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| chenhg5 | cc-connect | 1.4.0 |
cpe:2.3:a:chenhg5:cc-connect:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: unauthenticated remote code injection via POST /hook "exec" — ran as uid=0(root); exfiltrated PROOF_933d3cef5f38245c
No comments yet