(截至提交 5df942ab)存在一个认证绕过漏洞,其根本原因是大多数 REST API 路由的处理函数签名中缺少认证守卫。未经认证的攻击者无需提供有效凭证,即可通过直接访问这些未受保护的端点,对用户账户执行创建、更新、列表查询、检索和删除等操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| iot-ecology | rust-iot-platform | 0 ~ 5df942ab6bc46a3bf83dbee8c7970554f92c972d | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet