Skip to content

Latest commit

 

History

History
18 lines (12 loc) · 989 Bytes

CVE-2021-30234.md

File metadata and controls

18 lines (12 loc) · 989 Bytes

Background

China Mobile An Lianbao WF-1 router is an AX1800 router based on Qualcomm's five-core processor. It adopts a new generation of 11AX technology, 2.4G and 5G dual-band concurrently, and can provide a wireless rate of 1800M, providing high-speed and stable WiFi coverage

Description

China Mobile An Lianbao WF-1 router provide web interface /api/ZRIGMP/set_MLD_PROXY which receive parameters by POST request, and the parameter MLD_PROXY_WAN_CONNECT has a command injection vulnerability, An attacker can use the vulnerability to execute remote commands

Affect Versions

V1.0.1

Acknowledgements

repoter :Lewei Qu and Dongxiang Ke

References

https://www.cnvd.org.cn/flaw/show/CNVD-2021-03520

https://www.ebuy7.com/item/china-mobile-wireless-router-qualcomm-qiki-wifi6-routing-mesh-network-home-5g-dual-frequency-double-gigabit-port-wall-wall-high-speed-%E2%80%8B%E2%80%8Bhigh-power-enhanced-dormitory-students-an-lianbao-wf-1-628692180620

http://iot.10086.cn/?l=en-us