add Yealink_Device_Management_Platform_SSRF_CVE_2021_27561

This commit is contained in:
gobysec 2021-08-02 20:27:13 +08:00
parent 544904aaf7
commit 5f7195eb14
2 changed files with 10 additions and 0 deletions

View File

@ -0,0 +1,10 @@
# Yealink Device Management Platform SSRF (CVE-2021-27561)
Yealink DM (Device Management) platform offers a comprehensive management solution with key features Unified Deployment and Management, Real-Time Monitoring and Alarm, Remote Troubleshooting. By chaining a pre-auth SSRF vulnerability and a command injection vulnerability, it is possible to execute commands as root without authentication against this product, by sending a simple HTTPS request to the remote target.
**FOFA query rule**: [title="dm-v30"](https://fofa.so/result?qbase64=dGl0bGU9ImRtLXYzMCI%3D)
# Demo
![img](Yealink_Device_Management_Platform_SSRF_CVE_2021_27561.gif)

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.4 MiB