CVE-2020-8958: 针对使用 boa 服务器的 NetLink 路由器的经过身份验证的远程代码执行漏洞。
CVSS 评分: 7.2
漏洞类型: OS Command Injection
身份验证: 需要
受影响型号: HG323
Netlink 路由器中的 /boaform/admin/formPing 资源允许远程攻击者通过 target_addr 参数执行 OS Command Injection。
usage: CVE-2020-8958.py [-h] -i URL [-u [USER]] [-p [PASS]]
CVE-2020-8958: Authenticated remote code execution exploit
optional arguments:
-h, --help show this help message and exit
-i URL, --Url URL Target IP of router
-u [USER], --User [USER]
Username
-p [PASS], --Pass [PASS]
Password