References https://www.secrss.com/articles/52434 https://xlab.tencent.com/cn/2018/01/05/a-new-way-to-exploit-cve-2017-17215/ https://blog.csdn.net/GKD2019/article/details/146464960 https://zhuanlan.zhihu.com/p/314170234 https://foxcookie.github.io/2023/09/11/HG532e%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0(CVE-2017-17215)/ https://www.iotsec-zone.com/article/312 https://www.cnblogs.com/zzzh1/p/18819080 https://cymulate.com/blog/huawei-hg532-remote-code-exploit/ https://www.huawei.com/en/psirt/security-notices/huawei-sn-20171130-01-hg532-en https://nvd.nist.gov/vuln/detail/CVE-2017-17215 https://research.checkpoint.com/2017/good-zero-day-skiddie/ https://www.exploit-db.com/exploits/43414
Related Vulnerabilities全程云OA /OA/Common/API/Huawei.asmx SQL 注入漏洞PoCCVE-2019-19411: Huawei Firewall - Local File InclusionPoCCVE-2017-17215: 华为HG532e远程命令执行漏洞PoChuawei-hg532e-default-login: Huawei HG532e Default CredentialPoChuawei-dg8045-home-gateway-password-leakage: Huawei DG8045 deviceinfo 信息泄漏漏洞PoChuawei-auth-http-fileread: 华为Auth-HTTP服务器任意文件读取漏洞PoChuawei-home-gateway-hg659-fileread: Huawei Home Gateway Hg659 FilereadPoChuawei-HG532e-default-login: Huawei HG532e Default CredentialPoChuawei-authhttp-lfi: Huawei Auth Http Server - Arbitrary File ReadPoChuawei-hg255s-lfi: Huawei HG255s - Local File InclusionPoChuawei-hg659-lfi: HUAWEI HG659 - Local File InclusionPoChuawei-router-auth-bypass: Huawei Router - Authentication BypassPoChuawei-esight-detect: Huawei ESight Detect