# Exploit Title: CorgetGpsDget 2_3.2 - OS Command Injection # Date: 2026-07-05 # Exploit Author: Bytetobreach # Fofa server: "PTTServer" # Vendor Homepage: http://corget.com # Version: GpsDget 2_3.2, build 2020-09-01 (dget.version); product line Gps2.0 # Tested on Ubuntu. Binary reversed on Ghidra Debian. # Sink is in http/HttpHandler.cpp CHttpHandler::SendEmail # CVE: pending (requested) # # Description: # HTTP service (Server: PTTServer) unauthenticated handler reachable by SendEmail # method request header. The "Target" header recipient # header is unsafly concatenated into a system() call: # system("echo '
'|mail -r 'service@corget.com' -s '