Add Thecus NAS Post Auth Command Injection

This commit is contained in:
xiaoheihei1107 2021-08-14 18:56:41 +08:00 committed by GitHub
parent e073d616a6
commit 2b15b3d5d2
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -0,0 +1,9 @@
# Thecus NAS Post Auth Command Injection
Thecus N4800Eco NAS server control panel suffers from a command injection vulnerability.
FOFA **query rule**: [Elecom-Thecus-NAS](https://fofa.so/result?qbase64=YXBwPSJFbGVjb20tVGhlY3VzLU5BUyI%3D)
# Demo
![Thecus_NAS_Post_Auth_Command_Injection](Thecus_NAS_Post_Auth_Command_Injection.gif)