Orbi(RBS50)路由器WebUI POST请求Firefox正常curl报400错误
问题背景
我需要频繁重启Orbi(RBS50)路由器及卫星设备,Netgear已不再提供ssh/telnet访问权限,只能通过Web界面操作。在Firefox浏览器中操作完全正常:打开页面、完成Basic认证、点击重启按钮即可。我导出了Firefox开发者控制台中的对应curl命令,完整的登录及重启请求HAR文件可查看。
Firefox原生导出的curl命令(未修改)
- 通过Basic认证打开重启页面:
curl 'https://192.168.0.6/reboot.htm' -H 'User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0' -H 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8' -H 'Accept-Language: de,en-US;q=0.7,en;q=0.3' -H 'Accept-Encoding: gzip, deflate, br' -H 'DNT: 1' -H 'Connection: keep-alive' -H 'Upgrade-Insecure-Requests: 1' -H 'Sec-Fetch-Dest: document' -H 'Sec-Fetch-Mode: navigate' -H 'Sec-Fetch-Site: none' -H 'Sec-Fetch-User: ?1'
- 点击“Yes”按钮执行重启:
curl 'https://192.168.0.6/apply.cgi?/reboot_waiting.htm%20timestamp=71222162842' -X POST -H 'User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0' -H 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8' -H 'Accept-Language: de,en-US;q=0.7,en;q=0.3' -H 'Accept-Encoding: gzip, deflate, br' -H 'Content-Type: application/x-www-form-urlencoded' -H 'Origin: https://192.168.0.6' -H 'DNT: 1' -H 'Authorization: Basic YWRtaW46UGFzc3dvcnQwMA==' -H 'Connection: keep-alive' -H 'Referer: https://192.168.0.6/reboot.htm' -H 'Cookie: auth_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJleHAiOiI4OTg3NiIsImlzcyI6Ind3dy5uZXRnZWFyLmNvbSIsInN1YiI6Ik1vemlsbGEvNS4wIChYMTE7IFVidW50dTsgTGludXggeDg2XzY0OyBydjoxMDkuMCkgR2Vja28vMjAxMDAxMDEgRmlyZWZveC8xMDkuMCJ9.2b3420f66ed35dd347c38e280f6b0ebedfd5ee2fdd5b3ab53384965fb241c6ba' -H 'Upgrade-Insecure-Requests: 1' -H 'Sec-Fetch-Dest: document' -H 'Sec-Fetch-Mode: navigate' -H 'Sec-Fetch-Site: same-origin' -H 'Sec-Fetch-User: ?1' --data-raw 'submit_flag=reboot&yes=Ja+'
我的操作步骤及错误结果
- 使用curl带Basic认证访问重启页面,操作正常:可显示HTML内容并写入Cookie。
curl --insecure -c cookies.txt -b cookies.txt 'https://192.168.0.6/reboot.htm' -H 'User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0' -H 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8' -H 'Accept-Language: de,en-US;q=0.7,en;q=0.3' -H 'Accept-Encoding: gzip, deflate, br' -H 'DNT: 1' -H 'Connection: keep-alive' -H 'Upgrade-Insecure-Requests: 1' -H 'Sec-Fetch-Dest: document' -H 'Sec-Fetch-Mode: navigate' -H 'Sec-Fetch-Site: none' -H 'Sec-Fetch-User: ?1' -u "admin:Passwort00"
- 尝试发送POST请求执行重启:
curl --insecure -c cookies.txt -b cookies.txt 'https://192.168.0.6/apply.cgi?/reboot_waiting.htm%20timestamp=71222162842' -X POST -H 'User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0' -H 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8' -H 'Accept-Language: de,en-US;q=0.7,en;q=0.3' -H 'Accept-Encoding: gzip, deflate, br' -H 'Content-Type: application/x-www-form-urlencoded' -H 'Origin: https://192.168.0.6' -H 'DNT: 1' -H 'Authorization: Basic YWRtaW46UGFzc3dvcnQwMA==' -H 'Connection: keep-alive' -H 'Referer: https://192.168.0.6/reboot.htm' -H 'Upgrade-Insecure-Requests: 1' -H 'Sec-Fetch-Dest: document' -H 'Sec-Fetch-Mode: navigate' -H 'Sec-Fetch-Site: same-origin' -H 'Sec-Fetch-User: ?1' --data-raw 'submit_flag=reboot&yes=Ja+'
返回结果:
400 Bad Requestclasses.num.all.fontFamily = Courier; classes.num.all.fontSize = 10pt; <h1>400 Ungültige Anforderung</h1> Der vom Client angeforderte Vorgang wird vom Server nicht unterstützt.
Firefox中点击重启按钮完全正常,但curl执行POST请求却失败,尝试多种请求头组合仍未解决。
可能的解决方案
1. 替换动态timestamp参数
Firefox导出的timestamp=71222162842是会话绑定的动态值,不能直接复用。需要从第一步访问reboot.htm返回的HTML源码里提取当前有效的timestamp,替换到POST请求的URL中。
2. 移除重复的认证头
你同时用了-u参数和手动添加的Authorization: Basic ...头,可能触发服务器的认证冲突。建议移除POST请求中的Authorization头,仅保留-u参数或通过cookie传递认证信息。
3. 确保Cookie正确传递
可以直接从第一步生成的cookies.txt中提取auth_token值,在POST请求中手动添加Cookie头,比如:-H 'Cookie: auth_token=从cookies.txt中读取的实际值',避免cookie传递异常。
4. 简化请求头
去掉非必要的请求头(如Sec-Fetch-*、DNT),只保留核心的User-Agent、Accept、Content-Type、Referer、Origin,减少服务器拒绝请求的可能性。
修改后的POST请求示例(需替换timestamp和auth_token):
curl --insecure -b cookies.txt 'https://192.168.0.6/apply.cgi?/reboot_waiting.htm timestamp=新获取的时间戳' -X POST -H 'User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0' -H 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8' -H 'Content-Type: application/x-www-form-urlencoded' -H 'Origin: https://192.168.0.6' -H 'Referer: https://192.168.0.6/reboot.htm' --data-raw 'submit_flag=reboot&yes=Ja+' -u "admin:Passwort00"
内容的提问来源于stack exchange,提问作者Benjamin -

