CVE-2015-2049
published 2015-02-23CVE-2015-2049: Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated users to execute arbitrary code by…
PriorityP274critical9CVSS 2.0
AVNACLAuSCCICAC
EXPLOIT
EPSS
66.67%
99.2th percentile
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dcs-931l_firmware | <= 1.04 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP POST requests to the 'setFileUpload' endpoint on D-Link DCS-931L cameras, especially with multipart/form-data content type, which indicates an attempted arbitrary file upload exploit. ↗
- →Detect HTTP POST requests to 'setSystemAdmin' endpoint immediately following file uploads to '/sbin/chpasswd.sh', as this is the trigger mechanism used to execute the uploaded payload. ↗
- →Alert on HTTP 200 responses from D-Link DCS-931L containing the string 'File had been uploaded' in the response body, which confirms successful exploitation. ↗
- →Monitor for access to 'uploadfile.htm' on D-Link camera web interfaces; a 200 response with body containing 'Upload File' confirms the device is vulnerable. ↗
- →Detect WWW-Authenticate headers matching the realm 'DCS-931L' on network traffic to identify targeted devices during reconnaissance. ↗
- →Monitor for creation of hidden files (dot-prefixed filenames) under /tmp/ on Linux MIPS embedded devices, which is the payload staging location used by this exploit. ↗
- →Alert on HTTP User-Agent or process patterns matching 'alphapd', the web server process on D-Link DCS-931L cameras, to identify targeted devices. ↗
- ·The exploit requires valid credentials (authenticated access); default credentials (username: 'admin', password: blank) are used by the Metasploit module, so devices with default credentials are at highest risk. ↗
- ·The exploit targets Linux MIPS little-endian (mipsle) architecture payloads; detection and response tooling must account for this embedded platform architecture. ↗
- ·Firmware versions 1.01_B7 (2013-04-19) and 1.04_B1 (2014-04-21) are confirmed vulnerable; D-Link DCS-930L, DCS-932L, and DCS-933L are reportedly affected but untested. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT Possible CVE-2015-7547 Long Response to A lookup
suricata·2016-02-18·CVSS 8.1
CVE-2015-7547 [HIGH] ET EXPLOIT Possible CVE-2015-7547 Long Response to A lookup
ET EXPLOIT Possible CVE-2015-7547 Long Response to A lookup
Rule: alert udp any 53 -> $HOME_NET any (msg:"ET EXPLOIT Possible CVE-2015-7547 Long Response to A lookup"; flow:from_server; content:"|00 01|"; offset:4; depth:2; isdataat:2049; byte_test:1,&,128,2; byte_test:1,!&,64,2; byte_test:1,!&,32,2; byte_test:1,!&,16,2; byte_test:1,!&,8,2; byte_test:1,&,2,2; byte_test:1,!&,1,3; byte_test:1,!&,2,3; byte_test:1,!&,4,3; byte_test:1,!&,8,3; pcre:"/^.{6}[^\x00]+/Rs"; content:"|00 00 01 00 01|"; within:5; reference:cve,2015-7547; classtype:attempted-user; sid:2022543; rev:1; metadata:created_at 2016_02_18, cve CVE_2015_7547, confidence Medium, signature_severity Major, updated_at 2019_07_26;)
Suricata
ET EXPLOIT Possible CVE-2015-7547 Malformed Server Response A/AAAA
suricata·2016-02-18·CVSS 8.1
CVE-2015-7547 [HIGH] ET EXPLOIT Possible CVE-2015-7547 Malformed Server Response A/AAAA
ET EXPLOIT Possible CVE-2015-7547 Malformed Server Response A/AAAA
Rule: alert udp any 53 -> $HOME_NET any (msg:"ET EXPLOIT Possible CVE-2015-7547 Malformed Server Response A/AAAA"; flow:from_server; content:"|00 01 00 00 00 00 00 00|"; offset:4; depth:10; isdataat:2049; byte_test:1,&,128,2; byte_test:1,!&,64,2; byte_test:1,!&,32,2; byte_test:1,!&,16,2; byte_test:1,!&,8,2; byte_test:1,&,2,2; byte_test:1,!&,1,3; byte_test:1,!&,2,3; byte_test:1,!&,4,3; byte_test:1,!&,8,3; pcre:"/^(?:.[a-z0-9-]{2,}){2,}\x00\x00(?:\x01|\x1c)/Ri"; reference:cve,2015-7547; classtype:attempted-user; sid:2022545; rev:1; metadata:created_at 2016_02_18, cve CVE_2015_7547, confidence Medium, signature_severity Major, updated_at 2019_07_26;)
Suricata
ET EXPLOIT Possible 2015-7547 PoC Server Response
suricata·2016-02-18
CVE-2015-7547 ET EXPLOIT Possible 2015-7547 PoC Server Response
ET EXPLOIT Possible 2015-7547 PoC Server Response
Rule: alert udp any 53 -> $HOME_NET any (msg:"ET EXPLOIT Possible 2015-7547 PoC Server Response"; flow:from_server; content:"|83 80 00 01 00 00 00 00 00 00|"; offset:2; depth:10; isdataat:2049; pcre:"/^(?:.[a-z0-9-]{2,}){2,}\x00\x00(?:\x01|\x1c)/Ri"; reference:cve,2015-7547; classtype:attempted-user; sid:2022542; rev:1; metadata:created_at 2016_02_18, cve CVE_2015_7547, confidence Medium, signature_severity Major, updated_at 2019_07_26;)
Suricata
ET EXPLOIT Possible CVE-2015-7547 Long Response to AAAA lookup
suricata·2016-02-18·CVSS 8.1
CVE-2015-7547 [HIGH] ET EXPLOIT Possible CVE-2015-7547 Long Response to AAAA lookup
ET EXPLOIT Possible CVE-2015-7547 Long Response to AAAA lookup
Rule: alert udp any 53 -> $HOME_NET any (msg:"ET EXPLOIT Possible CVE-2015-7547 Long Response to AAAA lookup"; flow:from_server; content:"|00 01|"; offset:4; depth:2; isdataat:2049; byte_test:1,&,128,2; byte_test:1,!&,64,2; byte_test:1,!&,32,2; byte_test:1,!&,16,2; byte_test:1,!&,8,2; byte_test:1,&,2,2; byte_test:1,!&,1,3; byte_test:1,!&,2,3; byte_test:1,!&,4,3; byte_test:1,!&,8,3; pcre:"/^.{6}[^\x00]+/Rs"; content:"|00 00 1c 00 01|"; within:5; reference:cve,2015-7547; classtype:attempted-user; sid:2022544; rev:1; metadata:created_at 2016_02_18, cve CVE_2015_7547, confidence Medium, signature_severity Major, updated_at 2019_07_26;)
Suricata
ET EXPLOIT Possible 2015-7547 Malformed Server response
suricata·2016-02-17
CVE-2015-7547 ET EXPLOIT Possible 2015-7547 Malformed Server response
ET EXPLOIT Possible 2015-7547 Malformed Server response
Rule: alert udp any 53 -> $HOME_NET any (msg:"ET EXPLOIT Possible 2015-7547 Malformed Server response"; flow:from_server; content:"|00 01 00 00 00 00 00 00|"; offset:4; depth:8; isdataat:2049; byte_test:1,&,128,2; byte_test:1,!&,64,2; byte_test:1,!&,32,2; byte_test:1,!&,16,2; byte_test:1,!&,8,2; byte_test:1,&,2,2; byte_test:1,!&,1,3; byte_test:1,!&,2,3; byte_test:1,!&,4,3; byte_test:1,!&,8,3; pcre:"/^[^\x00]+\x00\x00\x01/R"; reference:cve,2015-7547; classtype:attempted-user; sid:2022531; rev:1; metadata:created_at 2016_02_17, cve CVE_2015_7547, confidence Medium, signature_severity Major, updated_at 2019_07_26;)
Exploit-DB
D-Link DCS-931L - Arbitrary File Upload (Metasploit)
exploitdb·2016-01-07
CVE-2015-2049 D-Link DCS-931L - Arbitrary File Upload (Metasploit)
D-Link DCS-931L - Arbitrary File Upload (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit4 [ /alphapd/ ] }
def initialize(info = {})
super(update_info(info,
'Name' => 'D-Link DCS-931L File Upload',
'Description' => %q{
This module exploits a file upload vulnerability in D-Link DCS-931L
network cameras. The setFileUpload functionality allows authenticated
users to upload files to anywhere on the file system, allowing system
files to be overwritten, resulting in execution of arbitrary commands.
This module has been tested successfully on a D-Link DCS-931L with
firmware versions 1.01_B7 (2013-04-19) and 1.04_B1 (2014-04-21).
D-Link DCS-930L, DCS-932L
Metasploit
D-Link DCS-931L File Upload
metasploit
D-Link DCS-931L File Upload
D-Link DCS-931L File Upload
This module exploits a file upload vulnerability in D-Link DCS-931L network cameras. The setFileUpload functionality allows authenticated users to upload files to anywhere on the file system, allowing system files to be overwritten, resulting in execution of arbitrary commands. This module has been tested successfully on a D-Link DCS-931L with firmware versions 1.01_B7 (2013-04-19) and 1.04_B1 (2014-04-21). D-Link DCS-930L, DCS-932L, DCS-933L models are also reportedly affected, but untested.
No writeups or analysis indexed.
http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10049http://www.kb.cert.org/vuls/id/377348https://www.exploit-db.com/exploits/39192/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10049http://www.kb.cert.org/vuls/id/377348https://www.exploit-db.com/exploits/39192/
2015-02-23
Published