Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-40113 PoC — Cisco Catalyst Passive Optical Network Series Switches 操作系统命令注入漏洞

Source
Associated Vulnerability
Title:Cisco Catalyst Passive Optical Network Series Switches 操作系统命令注入漏洞 (CVE-2021-40113)
Description:Cisco Catalyst Passive Optical Network Series Switches(Catalyst Pon Series Switches)是美国思科(Cisco)公司的一系列高性能、结构简单、易于维护的交换机。用于提供具有竞争力的网络解决方案。 Cisco Catalyst Passive Optical Network Series Switches 存在操作系统命令注入漏洞,该漏洞源于Cisco Catalyst PON系列交换机ONT基于web的管理界面对用户提供的输入
Description
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform c CVE project by @Sn0wAlice
Readme
# CVE-2021-40113

Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform command injection Modify the configuration For more information about these vulnerabilities, see the Details section of this advisory.

| authentication | complexity | vector |
| --- | --- | --- |
| NONE | LOW | NETWORK |

| confidentiality | integrity | availability |
| --- | --- | --- |
| PARTIAL | PARTIAL | PARTIAL |

## CVSS Score: **7.5**

## References

* https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catpon-multivulns-CE3DSYGr

## Brut File

* [CVE-2021-40113.json](./data_brut.json)



## About this repository
This repository is part of the project [Live Hack CVE](https://github.com/Live-Hack-CVE). Made by [Sn0wAlice](https://github.com/Sn0wAlice) for the people that care about security and need to have a feed of the latest CVEs. Hope you enjoy it, don't forget to star the repo and follow me on [Twitter](https://twitter.com/Sn0wAlice) and [Github](https://github.com/Sn0wAlice)
File Snapshot

[4.0K] /data/pocs/0802376d8f922479ee39ed3eac7caa4e49988342 ├── [2.4K] data_brut.json └── [1.2K] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.