CVE-2021-43469

image

Exploit Title: VINGA router has weak passwords and background command execution vulnerabilities.

product: VINGA WR-N300U

webserver: goahead

Author: CXAQHQ

TIME: 2021-11-01

Command execution vulnerabilities exist on the Ping and traceroute interfaces after login.

Run the IP addr command

avatar avatar

IDA looks at the vulnerability code

avatar