Post

Bohua Netdragon Firewall Users Xml Unauthorized Access

Bohua Netdragon Firewall Users Xml Unauthorized Access

Bohua NetDragon Firewall users.xml Unauthorized access

Vulnerability Description

Bohua NetDragon Firewall users.xml file can be read by any user, including the logged-in account password

Vulnerability Impact

Bohua NetDragon Firewall

Network surveying and mapping

Vulnerability reappears

Login page

img

Verify POC, read configuration file to obtain password Md5

1
/xml/users.xml

img

This post is licensed under CC BY 4.0 by the author.