大华ICC智能物联网管理平台 /evo-runs/v1.0/receive/response/file 文件读取漏洞

Description

大华ICC智能物联网管理平台是面向物联网设备提供集中接入、管理与智能分析的综合平台,广泛应用于安防物联网与设备统一管理场景。其接口 /evo-runs/v1.0/receive/response/file 缺乏有效身份验证,攻击者可发送特制 JSON 请求,通过 method=agent.module.log.file 并在 info.list 中指定 path 参数读取任意文件;服务端以 application/zip 附件形式返回,ZIP 内包含目标文件内容。成功利用可获取系统敏感配置与凭证信息。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities