Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-13025 PoC — Compal CH7465LG 输入验证错误漏洞

Source
Associated Vulnerability
Title:Compal CH7465LG 输入验证错误漏洞 (CVE-2019-13025)
Description:Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation. The attacker can send a maliciously modified POST (HTTP) request containing shell commands, which will be executed on the device, to an backend API endpoint of the cable modem.
Description
Connect Box CH7465LG (CVE-2019-13025)
Readme
# Connect Box CH7465LG (CVE-2019-13025)

# Information

This repository contains two PoCs for the `Connect Box CH7465LG` running on Firmware `CH7465LG-NCIP-6.12.18.24-5p8-NOSH` or older.

For more information have a look at [my blog](https://xitan.me/posts/connect-box-ch7465lg-rce/).

# Usage

## Unauthenticated Remote Code Execution

> $ python3 poc-rce.py <router_ip> <command>

## Unauthenticated Information Disclosure

> $ python3 poc-information-dump.py <router_ip>

# Credits

xitan 2019.
File Snapshot

[4.0K] /data/pocs/33d473258050649316ac3d46f754ea2e27a5c193 ├── [1.3K] poc-information-dump.py ├── [ 924] poc-rce.py ├── [ 497] README.md └── [ 116] requirements.txt 0 directories, 4 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →