Unauthenticated Command Injection in Netis Router


This week’s Metasploit release includes an exploit module for an unauthenticated command injection vulnerability in the Netis MW5360 router which is being tracked as CVE-2024-22729.

The vulnerability stems from improper handling of the password parameter within the router’s web interface which allows for command injection. Fortunately for attackers, the router’s login page authorization can be bypassed by simply deleting the authorization header, leading to the vulnerability. All router firmware versions up to V1.0.1.3442 are vulnerable.

Read more…
Source: Rapid7


Sign up for our Newsletter


Related:

  • NATO Cyber Security Centre experiments with secure network capable of withstanding attack by quantum computers

    March 2, 2022

    Scientists have predicted that quantum computers will one day be able to break some commonly used encryption methods. That’s why NATO and Allies are already testing post-quantum solutions. The NATO Cyber Security Centre (NCSC) has successfully tested secure communication flows in a post-quantum world using a Virtual Private Network (VPN) provided by the United Kingdom-based company Post-Quantum. ...

  • CISA Compiles Free Cybersecurity Services and Tools for Network Defenders

    February 18, 2022

    CISA has compiled and published a list of free cybersecurity services and tools to help organizations reduce cybersecurity risk and strengthen resiliency. This non-exhaustive living repository includes services provided by CISA, widely used open source tools, and free tools and services offered by private and public sector organizations across the cybersecurity community. Before turning to ...

  • Singapore to build quantum-safe network for critical infrastructure trials

    February 17, 2022

    Singapore is aiming to build a quantum-safe network that it hopes will showcase “crypto-agile connectivity” and facilitate trials with both public and private organisations. The initiative also includes a quantum security lab for vulnerability research. The three-year initiative is led by the Quantum Engineering Programme (QEP), with SG$8.5 million ($6.31 million) set aside to fund its ...

  • Critical MQTT-Related Bugs Open Industrial Networks to RCE Via Moxa

    February 11, 2022

    Critical security vulnerabilities in Moxa’s MXview web-based network management system open the door to an unauthenticated remote code execution (RCE) as SYSTEM on any unpatched MXview server, researchers warned this week. The five bugs, affecting versions 3.x to 3.2.2, score a collective 10 out of 10 on the CVSS vulnerability-severity scale, according to Claroty’s Team82 research ...

  • 277,000 routers exposed to Eternal Silence attacks via UPnP

    January 31, 2022

    A malicious campaign known as ‘Eternal Silence’ is abusing Universal Plug and Play (UPnP) turns your router into a proxy server used to launch malicious attacks while hiding the location of the threat actors. UPnP is a connectivity protocol optionally available in most modern routers that allows other devices on a network to create port forwarding ...

  • Millions of Routers Exposed to RCE by USB Kernel Bug

    January 11, 2022

    Millions of popular end-user routers are at risk of remote code execution (RCE) due to a high-severity flaw in the KCodes NetUSB kernel module. The module enables remote devices to connect to routers over IP and access any USB devices (such as printers, speakers, webcams, flash drives and other peripherals) that are plugged into them. This ...