Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-30065: mitrastar-code-execution/README.md at main · Sigmw/mitrastar-code-execution

MitraStar GPT-2741GNAC-N2 with firmware BR_g5.9_1.11(WVK.0)b32 was discovered to contain a remote code execution (RCE) vulnerability in the ping function.

CVE
#vulnerability#rce

Code execution on MitraStar GPT-2741GNAC-N2.

Should work on GPT-2741GNAC-N1.

Firmware: BR_g5.9_1.11(WVK.0)b32 (last version at this moment.)

Exploit: We can pass a pipe to execute commands with the ping diagnostic tool of the router.

Considering a variable $GATEWAY=192.168.15.1 (generally the MitraStar gateway)

We can access the panel in http://GATEWAY/padrao

After logging, we can go to this field: (Im logging with support user)

We can do a simple ping and see the tool working:

But a simple and poisonous shell pipe operator give us a possibilty to exec commands in operational system.

It seems we have permissions in root FS too: (Considering that I logged in using the support user, the password I used is the one under the router.)

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907