nginx 1.2.3
tcp/443
This vulnerability (with proof of concept (PoC) code) affects DVR/NVR devices built using the HiSilicon hi3520d and similar system on a chip (SoC).
Exploiting the vulnerabilities lead to unauthorized remote code execution (RCE) using only the web interface, causing full takeover of the exploited device
Severity: high
Fingerprint: 321975614123c6c05f83e99b2711ab76525057b7525057b7525057b7525057b7
Found HiSiliconDVR firmware: Hardware: General HI3516EV100_50H20L_S38 Vulnerable to multiple issues : LFI, possibly RCE
This vulnerability (with proof of concept (PoC) code) affects DVR/NVR devices built using the HiSilicon hi3520d and similar system on a chip (SoC).
Exploiting the vulnerabilities lead to unauthorized remote code execution (RCE) using only the web interface, causing full takeover of the exploited device
Severity: high
Fingerprint: 321975614123c6c05f83e99b336d0f88b4e6f2adb4e6f2adb4e6f2adb4e6f2ad
Found HiSiliconDVR firmware: Hardware: General NBD8004R-PL Vulnerable to multiple issues : LFI, possibly RCE
Open service 42.113.186.161:443
2024-09-10 07:28
HTTP/1.1 400 Bad Request Server: nginx/1.2.3 Date: Tue, 10 Sep 2024 07:28:38 GMT Content-Type: text/html Transfer-Encoding: chunked Connection: close Page title: 400 The plain HTTP request was sent to HTTPS port <html> <head><title>400 The plain HTTP request was sent to HTTPS port</title></head> <body bgcolor="white"> <center><h1>400 Bad Request</h1></center> <center>The plain HTTP request was sent to HTTPS port</center> <hr><center>nginx/1.2.3</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page -->