Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-27174 PoC — MajorDoMo 代码注入漏洞

Source
Associated Vulnerability
Title:MajorDoMo 代码注入漏洞 (CVE-2026-27174)
Description:MajorDoMo是MajorDoMo社区的一个开源DIY智能家居自动化平台。 MajorDoMo存在代码注入漏洞,该漏洞源于modules/panel.class.php中的包含顺序错误导致执行在缺少exit语句的redirect()调用后继续,允许未经验证的请求到达inc_panel_ajax.php中的ajax处理程序,该处理程序将来自GET参数的用户输入直接传递给eval(),可能导致远程代码执行。
Description
MajorDoMo contains a remote code execution caused by an include order bug and lack of exit after redirect in admin panel's PHP console, letting unauthenticated attackers execute arbitrary PHP code via crafted GET requests.
File Snapshot

id: CVE-2026-27174 info: name: MajorDoMo - Unauthenticated RCE author: 0x_Akoko severity: cri ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.