Description 网神SecFox运维安全管理与审计系统 authService接口处使用存在漏洞 fastjson 组件,未授权的攻击者可通过fastjson序列化漏洞对系统发起攻击获取服务器权限。
References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%BD%91%E7%A5%9E/%E7%BD%91%E7%A5%9ESecFox%E8%BF%90%E7%BB%B4%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E4%B8%8E%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9FFastJson%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96RCE%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/3714177.html https://www.ddpoc.com/DVB-2024-8654.html https://github.com/adysec/POC/blob/main/wpoc/%E7%BD%91%E7%A5%9E/%E7%BD%91%E7%A5%9ESecFox%E8%BF%90%E7%BB%B4%E5%AE%89%E5%85%A8%E7%AE%A1%E7%90%86%E4%B8%8E%E5%AE%A1%E8%AE%A1%E7%B3%BB%E7%BB%9FFastJson%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96RCE%E6%BC%8F%E6%B4%9E.md https://blog.csdn.net/weixin_71604403/article/details/136404241
Related VulnerabilitiesPoCvlife-fastjson-rce: Vlife FastJSON - Remote Code Execution天锐绿盾审批系统 endCallback fastjson 反序列化漏洞天锐绿盾审批系统 findTrusteeByFilter fastjson 反序列化漏洞天锐绿盾审批系统 findTrusteeBydeptId fastjson 反序列化漏洞天锐绿盾审批系统 updateToRead fastjson 反序列化漏洞天锐绿盾审批系统 findUserTrustees fastjson 反序列化漏洞天锐绿盾审批系统 mergeQuery fastjson 反序列化漏洞PoC天锐绿盾审批系统 editConfigVal fastjson 反序列化漏洞PoC网神SecFox运维安全管理与审计系统 /3.0/authService/login 命令执行漏洞天锐绿盘云文档安全管理平台存在FastJson反序列化漏洞fastjson-rce-all: Fastjson Deserialization RCEhikvision-center-fastjson-rce: 海康威视综合安防-运行管理中心-Fastjson-远程命令执行漏洞