Advisories

Zbtlink MQWrt infosrvd Command Injection

Go Back
severity
critical
date
Affecting
  • WE1326 <= 19.1101

  • WE2426-C <= 19.1112

  • WE357 <= 19.1101

  • WE5926 <= 19.1101

  • WE5926-EC_QP <= 20.0516

  • WE5926-WD <= 19.1101

  • WE826-Q <= 19.1101

  • WE826-T2 <= 19.1101

  • WE826-WD <= 19.1101

  • WF3526-P <= 19.051

  • WG108 <= 19.1101

  • WG3526 <= 19.1101

  • CTN720-W1 <= 19.1101

  • LF-1541 <= 19.1101

  • MT7620N <= 19.1101

  • WRC1 <= 20.0622

CWE
  • CWE-321 Use of Hard-coded Cryptographic Key
  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS
9.3
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References
Credit
Jacob Baines of VulnCheck
Description
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.

Ready to get Started?

Explore VulnCheck, a next-generation Cyber Threat Intelligence platform, which provides exploit and vulnerability intelligence to help you prioritize and remediate vulnerabilities that matter.
  • Vulnerability Prioritization
    Prioritize vulnerabilities that matter based on the threat landscape and defer vulnerabilities that don't.
  • Early Warning System
    Real-time alerting of changes in the vulnerability landscape so that you can take action before the attacks start.