Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-29337 PoC — C-DATA FD702XW-X-R430 操作系统命令注入漏洞

Source
Associated Vulnerability
Title:C-DATA FD702XW-X-R430 操作系统命令注入漏洞 (CVE-2022-29337)
Description:C-DATA FD702XW-X-R430是中国C-DATA公司的一款路由器。 C-DATA FD702XW-X-R430 v2.1.13_X001 存在操作系统命令注入漏洞,该漏洞源于formlanipv6中va_cmd参数缺少对于数据的转义和过滤。攻击者通过精心设计的HTTP请求利用该漏洞执行任意命令。
Description
C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.
Readme
# CVE-2022-29337
C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.
File Snapshot

[4.0K] /data/pocs/cdea9bb8a97dfe51408cae6620f496147a00e1f7 ├── [4.3K] exploit_lanipv6.py ├── [ 247] README.md └── [1.5K] reverse_shell_mipsle.c 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.