
Telesquare SDT-CW3B1 1.1.0 版本存在操作系统命令注入漏洞。远程攻击者可利用该漏洞在无需任何身份验证的情况下执行操作系统命令。
git clone https://github.com/yigexioabai/CVE-2022-26134-cve1.git
cd CVE-2022-26134-cve1
pip3 install -r requirements.txt
Place CVE-2022-26134_RCE.py in the pocsuite3\pocs directory
cd pocs
Single URL:
pocsuite -r CVE-2022-26134_RCE.py -u url
Multiple URLs:
pocsuite -r CVE-2022-26134_RCE.py -f url.txt (file containing URLs) --verify
This tool is intended only for legally authorized enterprise security construction activities. If you need to test the usability of this tool, please set up your own testing environment.
When using this tool for testing, you should ensure that the activity complies with local laws and regulations, and that you have obtained sufficient authorization. Do not scan non-authorized targets.
If you engage in any illegal activities while using this tool, you shall bear the corresponding consequences. We will not assume any legal or joint liability.