GobyVuls/SonicWall/SonicWall_SSL-VPN_RCE
2021-02-04 15:57:03 +08:00
..
2021-02-04 15:57:03 +08:00

SonicWall SSL-VPN RCE

There are vulnerabilities in the historical version of SonicWall SSL-VPN. Remote attackers use CGI programs to handle logic vulnerabilities and construct malicious User-Agents, which can cause remote arbitrary command execution and gain host control authority.

FOFA query rule: app="SonicWALL-SSL-VPN"

Demo