Post

Feiyuxing Home Smart Routing Cookie Cgi Permission Bypass

Feiyuxing Home Smart Routing Cookie Cgi Permission Bypass

Feiyuxing Home Smart Routing Cookie.cgi Permission Bypass

Vulnerability Description

Feiyuxing Home smart routing has permission bypass, accessing unauthorized administrator pages through Drop-specific request packages

Vulnerability Impact

Flying Fish Star Home Smart Routing

Flying Fish Star Enterprise-level intelligent Internet behavior management system

Network surveying and mapping

Vulnerability reappears

The login page is as follows

img

Cookie.cgi is requested when accessing index.html

https://xxx.xxx.xxx.xxx/index.html

Page packet capture Drop cookie.cgi

img

Jump backend to obtain permissions

img

If you gain something, just like it

This post is licensed under CC BY 4.0 by the author.