Microhard Systems 3G/4G 蜂窝以太网设备download.sh文件-任意文件包含漏洞

Description

【漏洞对象】Microhard Systems 【涉及版本】Microhard Systems 3G/4G 蜂窝以太网设备 【漏洞描述】 MicrohardSystems3G/4G蜂窝以太网和串行网关设备的/cgi-bin/webif/download.sh文件中script参数存在任意文件包含,可包含配置文件查看用户名密码。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities