diff --git a/exposed-panels/netis-router.yaml b/exposed-panels/netis-router.yaml new file mode 100644 index 0000000000..059004af5f --- /dev/null +++ b/exposed-panels/netis-router.yaml @@ -0,0 +1,29 @@ +id: netis-router + +info: + name: Netis Router Login + author: gy741 + severity: info + reference: https://www.tacnetsol.com/blog/cve-2019-8985-rce + tags: panel,login,router + +requests: + - method: GET + path: + - '{{BaseURL}}/login.htm' + + matchers-condition: or + matchers: + - type: word + part: body + words: + - 'AP setup' + + - type: word + part: header + words: + - 'Server: netis' + + - type: status + status: + - 200