CVE-2015-6018
published 2015-12-31CVE-2015-6018: The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via…
PriorityP279critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
20.62%
97.2th percentile
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | pmg5318-b20a_firmware | <= v100aanc0b5 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP POST requests to /diagnostic/diagnostic_general.cgi containing shell metacharacters (e.g., semicolons, pipes) in the PingIPAddr parameter, which indicates OS command injection attempts. ↗
- →Alert on multipart/form-data POST requests to the diagnostic CGI endpoint where the PingIPAddr field contains characters beyond a valid IP address (e.g., ';', '|', '`', '$'). ↗
- →Successful exploitation results in commands running as root; look for /etc/shadow read attempts or other sensitive file access originating from the web server process. ↗
- ·Vulnerability is present only on firmware versions prior to 1.00(AANC.2)C0; the specific tested version is V100AANC0b5. Devices already patched to 1.00(AANC.2)C0 or later are not affected. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
ZYXEL PMG5318-B20A - OS Command Injection
exploitdb·2015-10-14·CVSS 9.8
CVE-2015-6018 [CRITICAL] ZYXEL PMG5318-B20A - OS Command Injection
ZYXEL PMG5318-B20A - OS Command Injection
---
# Exploit Title: [ZyXEL PMG5318-B20A OS Command Injection Vulnerability]
# Discovered by: Karn Ganeshen
# CERT VU# 870744
# Vendor Homepage: [www.zyxel.com]
# Version Reported: [Firmware version V100AANC0b5]
# CVE-2015-6018 [http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6018]
*Vulnerability Details*
CWE-20 : Improper Input
Validation - CVE-2015-6018
The diagnostic ping function's PingIPAddr parameter in the ZyXEL
PMG5318-B20A, firmware version V100AANC0b5, does not properly validate user
input. An attacker can execute arbitrary commands as root.
*OS Command Injection PoC*
The underlying services are run as 'root'. It therefore, allows dumping
system password hashes.
*HTTP Request*
POST /diagnostic/diagnostic_general.cgi HTTP/
Exploit-DB
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (2)
exploitdb·2015-09-29·CVSS 9.8
CVE-2015-6922 [CRITICAL] Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (2)
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (2)
---
Kaseya VSA is an IT management platform for small and medium corporates.
From its console you can control thousands of computers and mobile
devices. So that if you own the Kaseya server, you own the organisation.
With this post I'm also releasing two Metasploit modules ([E1], [E2])
and a Ruby file ([E3]) that exploit the vulnerabilities described below.
A special thanks to ZDI for assisting with the disclosure of these
vulnerabilities. The full advisory text is below, but can also be
obtained from my repo at [E4].
[E1] https://github.com/rapid7/metasploit-framework/pull/6018
[E2] https://github.com/rapid7/metasploit-framework/pull/6019
[E3] https://raw.githubusercontent.com/pedrib/PoC/master/exploits/kazPwn.rb
No writeups or analysis indexed.
http://www.securitytracker.com/id/1034553https://www.exploit-db.com/exploits/38455/https://www.kb.cert.org/vuls/id/870744https://www.kb.cert.org/vuls/id/BLUU-9ZQU2Rhttp://www.securitytracker.com/id/1034553https://www.exploit-db.com/exploits/38455/https://www.kb.cert.org/vuls/id/870744https://www.kb.cert.org/vuls/id/BLUU-9ZQU2R
2015-12-31
Published