""ET EXPLOIT ZBL EPON ONU Broadband Router Remote Privilege Escalation Inbound M1""
SID: 2032780
Revision: 2
Class Type: attempted-admin
Metadata: attack_target Networking_Equipment, created_at 2021_04_19, updated_at 2021_04_19
Reference:
Protocol: tcp
Source Network: any
Source Port: any
Destination Network: $HOME_NET
Destination Port: $HTTP_PORTS
Flow: established,to_server
Contents:
-
Value: "POST"
-
Value: ".config"
-
Value: "CMD=CONFIG&GO=index.asp&TYPE=CONFIG"
Within:
PCRE: "/.config$/U"
Special Options:
-
http_method
-
http_uri
-
http_client_body