Skip to content

Latest commit

 

History

History
33 lines (20 loc) · 1.27 KB

WAVLINK AC1200_check_live.md

File metadata and controls

33 lines (20 loc) · 1.27 KB

0x01 Vulnerability description

A vulnerability is in the 'live_check.shtml' page of the AERIAL X 1200M,Firmware package version M79X3.V5030.180719

Unauthorized users can obtain the key information of the router by visiting:

http://xxx.xxx.xxx.xxx/live_check.shtml

0x02 Affected version

WAVLINK AERIAL X 1200M

0x03 Vulnerability

Under the live_check.shtml file, use the exec cmd function to execute the command

image-20220518145059172

0x04 PoC verification

image-20220518145211411

image-20220518145246880

image-20220518145313942

In the live_check.shtml interface, it contains various information of the router, such as: firmware version, MAC address, etc., and even information such as the running process of the router.

0x05 Acknowledgement

Penwei.Huang