cg33 CC-Connect是cg33个人开发者的一款网络连接设备。 cg33 CC-Connect 1.4.1及之前版本存在命令注入漏洞,该漏洞源于Management API组件中core/engine.go文件的shellExecCommand函数对exec参数的操作,可能导致os命令注入。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| chenhg5 | cc-connect | 1.4.0 |
affected |
1.4.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| chenhg5 | cc-connect | 1.4.0 |
cpe:2.3:a:chenhg5:cc-connect:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: os command injection via Management API exec arg -> shellExecCommand; observed: uid=0(root) gid=0(root) groups=0(root); exfiltrated PROOF_0199d0d0fd2bffaf
No comments yet