Skip to content

feat(cve-2016-15048): Add Nuclei template for HiBOS RCE#14669

Closed
DanLika wants to merge 2 commits intoprojectdiscovery:mainfrom
DanLika:DanLika-patch-1
Closed

feat(cve-2016-15048): Add Nuclei template for HiBOS RCE#14669
DanLika wants to merge 2 commits intoprojectdiscovery:mainfrom
DanLika:DanLika-patch-1

Conversation

@DanLika
Copy link
Copy Markdown

@DanLika DanLika commented Jan 1, 2026

This PR adds a Nuclei template for CVE-2016-15048, an unauthenticated blind command injection vulnerability in AMTT Hotel Broadband Operation System (HiBOS).

The template targets the /manager/radius/server_ping.php endpoint and uses a time-based detection method. It injects a sleep command in the ip parameter and verifies the vulnerability by checking if the response time is delayed.

/claim #14655

This PR adds a Nuclei template for CVE-2016-15048, an unauthenticated blind command injection vulnerability in AMTT Hotel Broadband Operation System (HiBOS).

The template targets the `/manager/radius/server_ping.php` endpoint and uses a time-based detection method. It injects a `sleep` command in the `ip` parameter and verifies the vulnerability by checking if the response time is delayed.

/claim projectdiscovery#14655
@pussycat0x pussycat0x added the Done Ready to merge label Jan 1, 2026
@pussycat0x
Copy link
Copy Markdown
Contributor

We already received PR for this #14656, Thank you for participating in the Bounty Claim Program.

@pussycat0x pussycat0x closed this Jan 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants