References https://zhuanlan.zhihu.com/p/626793428 https://www.ddpoc.com/DVB-2021-4284.html https://github.com/Sec-Fork/POC-20250106 https://zhuanlan.zhihu.com/p/626215120 https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/AVCON/avcon%E7%BB%BC%E5%90%88%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://github.com/zan8in/wy876-POC/blob/main/AVCON/AVCON-%E7%B3%BB%E7%BB%9F%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0download.action%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/2232235.html
Related VulnerabilitiesAVCON-系统管理平台存在sql注入PoCavcon6-download.action-download-file-read: AVCON6 系统管理平台 download.action 任意文件下载漏洞PoCavcon6-org-execl-file-download: AVCON6 系统管理平台 org_execl_download.action 任意文件下载漏洞PoCavcon6-execl-lfi: AVCON6 org_execl_download.action - Arbitrary File DownloadPoCavcon6-lfi: AVCON6 - Arbitrary File Download华平信息 AVCON系统管理平台 download.action 未授权 任意文件读取漏洞华平信息 AVCON网络视频服务系统 editusercommit.php 任意用户重置密码漏洞AVCON-网络视频服务系统 editusercommit.php 任意用户密码重置漏洞Avcon综合管理平台 存在SQL注入华平信息技术股份有限公司 AVCON6 系统管理平台存在远程代码执行漏洞AVCON6 org_execl_download.action 任意文件下载AVCON多媒体通信系统-任意文件下载