Description Tosei 自助洗衣机 /cgi-bin/view_data.php 接口存在文件读取漏洞。攻击者可通过传入特定参数读取服务器上的任意文件,进而获取敏感信息,危及设备及系统安全。
References https://nvd.nist.gov/vuln/detail/CVE-2024-43022 https://www.tenable.com/cve/CVE-2024-43022 https://dbugs.ptsecurity.com/vulnerability/PT-2024-30257 https://github.com/advisories/GHSA-grxj-hmrx-25w5 https://avd.aquasec.com/nvd/2024/cve-2024-43022/ https://gist.github.com/b0rgch3n/6ba0b04da7e48ead20f10b15088fd244
Related Vulnerabilities畅捷通 T+ POSSyncService.asmx 接口SQL注入漏洞PoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File UploadServiceNow-AI-Platform /assessment_thanks.do 代码执行漏洞(CVE-2026-6875)PoCCVE-2026-6875: ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE金蝶EAS /ormrpc/services/BSHService 代码执行漏洞用友U8Cloud /ServiceDispatcherServlet 文件上传漏洞用友 U8cloud /service/XChangeServlet SQL 注入漏洞关于NC系统BapAnaRepDefService的sql注入漏洞的安全通告时空智友ERP系统 /formservice updater.uploadStudioFile 文件上传漏洞广联达OA /Mail/Services/EmailAccountOrgUserService.asmx/GetUserEmailByOrgEmails XML 外部实体注入漏洞Nezha /api/v1/server/1/service 信息泄露漏洞(CVE-2026-49397)广联达OA /Org/service/Service.asmx/GetChangeUsers 信息泄露漏洞广联达OA /GTP/IM/Services/Group/Broadcast/MsgBroadcastContent.aspx SQL 注入漏洞