Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2017-17215 PoC — Huawei HG532 安全漏洞

Source
Associated Vulnerability
Title: Huawei HG532 安全漏洞 (CVE-2017-17215)
Description:Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.
Description
A Remote Code Execution (RCE) exploit for Huawei HG532d based on CVE-2017-17215 vulnerability. Modded from original PoC code from exploit-db.com
Readme
# HG532d RCE Exploit

## Overview
A Remote Code Execution (RCE) exploit based on [CVE-2017-17215](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17215) vulnerability. Modded from original PoC code from [exploit-db.com](https://www.exploit-db.com/exploits/43414) to work on  Huawei HG532d Home Gateway Routers.

## Description
This RCE exploit is based on CVE-2017-17215 which exploits vulnerabilities
in the UPnP process running on the Huawei HG532 series of home routers. The
original exploit from [exploit-db.com](https://www.exploit-db.com/exploits/43414) targets HG532 Home Routers.

This exploit, with a mod done to the HTTP POST Request, bypasses the input 
sanitation done by the router - which allows the original exploit to 
work with HG532d routers.

### Description of CVE:
Huawei HG532d with some customized versions has a remote code execution vulnerability. 
An authenticated attacker could send malicious packets to port 37215 to launch attacks.


## References
CVE Details: https://nvd.nist.gov/vuln/detail/CVE-2017-17215

Original PoC exploit source: https://www.exploit-db.com/exploits/43414

CheckPoint Vulnerability Report: https://research.checkpoint.com/2017/good-zero-day-skiddie/

Huawei Security Notice: https://www.huawei.com/en/psirt/security-notices/huawei-sn-20171130-01-hg532-en
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →