CVE-2022-33174: Powertek Firmware <3.30.30 - Authorization Bypass

CVE-2022-33174: Powertek Firmware <3.30.30 - Authorization Bypass-渗透云记 - 专注于网络安全与技术分享
CVE-2022-33174: Powertek Firmware <3.30.30 - Authorization Bypass
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-33174: Powertek Firmware <3.30.30 – Authorization Bypass

漏洞描述

Powertek firmware (multiple brands) before 3.30.30 running Power Distribution Units are vulnerable to authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享