mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-05-05 10:16:59 +00:00
Ricon Industrial Cellular Router apply.cgi RCE
The router suffers from an authenticated OS command injection vulnerability, This can be exploited to inject and execute arbitrary shell commands as the admin user via the ping_server_ip POST parameter. Also vulnerable to Heartbleed.
FOFA query rule: body="Industrial Cellular" && server="WEB-ROUTER"