SMA1000 设备的“Work Place”接口存在一个预认证阶段的服务端请求伪造(SSRF)漏洞,原因是存在一条非预期的替代访问路径。远程未认证的攻击者可能利用该漏洞,通过非授权的访问路径获取对敏感功能的非授权访问权限,并执行非授权的操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet