0x27 / CiscoRV320Dump

CVE-2019-1652 /CVE-2019-1653 Exploits For Dumping Cisco RV320 Configurations & Debugging Data AND Remote Root Exploit!
MIT License
225 stars 71 forks source link

Add patch bypass in command injection #7

Open 0x27 opened 5 years ago

0x27 commented 5 years ago

The patch for this failed miserably. We already evade the curl blacklisting by using requests, however we will need to very slightly tweak our command injection payload to evade a blacklist against the ' (0x27, lol) character.

I'll implement and test this, and verify it works on both old and new firmwares.