CVE-2018-6000
published 2018-01-22CVE-2018-6000: An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for…
PriorityP188critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
84.20%
99.7th percentile
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and consequently obtain remote administrative access, via a crafted request. This is available to unauthenticated attackers in conjunction with CVE-2018-5999.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| asus | asuswrt | < 3.0.0.4.384_10007 | 3.0.0.4.384_10007 |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
0x0c 0x15 0x33 0x00
- →Detect unauthenticated HTTP POST requests to /vpnupload.cgi containing the multipart form field 'ateCommand_flag' set to '1', which enables PKT_SYSCMD mode on the router. ↗
- →Monitor for UDP packets to port 9999 (infosvr) with the header byte sequence 0x0C 0x15 0x33 0x00 (NET_SERVICE_ID_IBOX_INFO / NET_PACKET_TYPE_CMD / NET_CMD_ID_MANU_CMD), indicating an attempt to send a PKT_SYSCMD command. ↗
- →Alert on inbound UDP 512-byte packets to port 9999 on AsusWRT devices containing a shell command string such as '/usr/sbin/telnetd -l /bin/sh', indicating active exploitation for remote shell spawning. ↗
- →Detect the authentication bypass condition: unauthenticated POST requests reaching handler->input() in the AsusWRT HTTP server, which should normally require auth_result == 0. ↗
- →After exploitation, watch for new unexpected TCP listening ports (random high ports) on AsusWRT devices, as the exploit starts telnetd on a random port above 1024. ↗
- ·The exploit chain requires CVE-2018-5999 (auth bypass) to be present alongside CVE-2018-6000; CVE-2018-6000 alone is not directly exploitable by an unauthenticated attacker without the auth bypass. ↗
- ·The exploit was confirmed on AsusWRT v3.0.0.4.380.7743 (RT-AC68U) and may affect all versions prior to v3.0.0.4.384.10007; detections should be scoped to these firmware versions. ↗
- ·The attack vector is LAN-only (local network); the infosvr UDP service on port 9999 and the HTTP server are not expected to be reachable from the WAN in default configurations. ↗
- ·CVE-2018-6000 can also be abused to overwrite the web interface admin password and enable SSH, providing an alternative RCE path beyond the infosvr PKT_SYSCMD method. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-92f5-6w73-42pg: An issue was discovered in AsusWRT before 3
ghsa_unreviewed·2022-05-13·CVSS 9.8
CVE-2018-6000 [CRITICAL] CWE-862 GHSA-92f5-6w73-42pg: An issue was discovered in AsusWRT before 3
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and consequently obtain remote administrative access, via a crafted request. This is available to unauthenticated attackers in conjunction with CVE-2018-5999.
VulnCheck
ASUS asuswrt Missing Authorization
vulncheck·2018·CVSS 9.8
CVE-2018-6000 [CRITICAL] ASUS asuswrt Missing Authorization
ASUS asuswrt Missing Authorization
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and consequently obtain remote administrative access, via a crafted request. This is available to unauthenticated attackers in conjunction with CVE-2018-5999.
Affected: ASUS asuswrt
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.bitsight.com/blog/rondodox-botnet-infrastructure-analysis
Cisco
Cisco NX-OS Software for Nexus 5500, 5600, and 6000 Series Switches Precision Time Protocol Denial of Service Vulnerability
vendor_cisco·2018-10-17·CVSS 8.6
CVE-2018-0378 [HIGH] CWE-20 Cisco NX-OS Software for Nexus 5500, 5600, and 6000 Series Switches Precision Time Protocol Denial of Service Vulnerability
Cisco NX-OS Software for Nexus 5500, 5600, and 6000 Series Switches Precision Time Protocol Denial of Service Vulnerability
A vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Series Switches running Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to a lack of protection against PTP frame flood attacks. An attacker could exploit this vulnerability by sending large streams of malicious IPv4 or IPv6 PTP traffic to the affected device. A successful exploit could allow the attacker to cause a DoS condition, impacting the traffic passing through the device.
Cisco has released software updates that address this vulnerability. There are no
Cisco
Cisco NX-OS Software for Nexus 5500, 5600, and 6000 Series Switches Precision Time Protocol Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0378 Cisco NX-OS Software for Nexus 5500, 5600, and 6000 Series Switches Precision Time Protocol Denial of Service Vulnerability
CVE-2018-0378: Cisco NX-OS Software for Nexus 5500, 5600, and 6000 Series Switches Precision Time Protocol Denial of Service Vulnerability
A vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Series Switches running Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of protection against PTP frame flood attacks. An attacker could exploit this vulnerability by sending large streams of malicious IPv4 or IPv6 PTP traffic to the affected device. A successful exploit could allow the attacker to cause a DoS condition, impacting the traffic passing through the device. Cisco has released software updates that address this vulnerability
No detection rules found.
Exploit-DB
AsusWRT LAN - Remote Code Execution (Metasploit)
exploitdb·2018-02-26
CVE-2018-6000 AsusWRT LAN - Remote Code Execution (Metasploit)
AsusWRT LAN - Remote Code Execution (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'AsusWRT LAN Unauthenticated Remote Code Execution',
'Description' => %q{
The HTTP server in AsusWRT has a flaw where it allows an unauthenticated client to
perform a POST in certain cases. This can be combined with another vulnerability in
the VPN configuration upload routine that sets NVRAM configuration variables directly
from the POST request to enable a special command mode.
This command mode can then be abused by sending a UDP packet to infosvr, which is running
on port UDP 9999 to directly execute commands as root.
This exploit leverages that to start telnetd in a random
Exploit-DB
AsusWRT Router < 3.0.0.4.380.7743 - LAN Remote Code Execution
exploitdb·2018-01-22·CVSS 9.8
CVE-2018-6000 [CRITICAL] AsusWRT Router < 3.0.0.4.380.7743 - LAN Remote Code Execution
AsusWRT Router > Unauthenticated LAN remote code execution in AsusWRT
>> Discovered by Pedro Ribeiro ([email protected]), Agile Information Security
Disclosure: 22/01/2018 / Last updated: 25/01/2018
>> Background and summary
AsusWRT is the operating system used in mid range and high end Asus routers. It is based on Linux, but with a sleek web UI and a slimmed down profile suitable for running on resource constrained routers.
Thankfully ASUS is a responsible company, and not only they publish the full source code as required by the GPL, but they also give users full root access to their router via SSH. Overall the security of their operating system is pretty good, especially when compared to other router manufacturers.
However due to a number of coding errors, it is possible for an unauth
Metasploit
AsusWRT LAN Unauthenticated Remote Code Execution
metasploit
AsusWRT LAN Unauthenticated Remote Code Execution
AsusWRT LAN Unauthenticated Remote Code Execution
The HTTP server in AsusWRT has a flaw where it allows an unauthenticated client to perform a POST in certain cases. This can be combined with another vulnerability in the VPN configuration upload routine that sets NVRAM configuration variables directly from the POST request to enable a special command mode. This command mode can then be abused by sending a UDP packet to infosvr, which is running on port UDP 9999 to directly execute commands as root. This exploit leverages that to start telnetd in a random port, and then connects to it. It has been tested with the RT-AC68U running AsusWRT Version 3.0.0.4.380.7743.
https://blogs.securiteam.com/index.php/archives/3589https://github.com/pedrib/PoC/blob/master/advisories/asuswrt-lan-rce.txthttps://raw.githubusercontent.com/pedrib/PoC/master/exploits/metasploit/asuswrt_lan_rce.rbhttps://www.exploit-db.com/exploits/43881/https://www.exploit-db.com/exploits/44176/https://blogs.securiteam.com/index.php/archives/3589https://github.com/pedrib/PoC/blob/master/advisories/asuswrt-lan-rce.txthttps://raw.githubusercontent.com/pedrib/PoC/master/exploits/metasploit/asuswrt_lan_rce.rbhttps://www.exploit-db.com/exploits/43881/https://www.exploit-db.com/exploits/44176/
2018-01-22
Published
Exploited in the wild