GobyVuls/Ricon/Ricon Industrial Cellular Router apply.cgi RCE

Ricon Industrial Cellular Router apply.cgi RCE

The router suffers from an authenticated OS command injection vulnerability, This can be exploited to inject and execute arbitrary shell commands as the admin user via the ping_server_ip POST parameter. Also vulnerable to Heartbleed.

FOFA query rule: body="Industrial Cellular" && server="WEB-ROUTER"

Demo