CVE-2013-10049
CRITICALRaidsonic IB-NAS5220 and IB-NAS4220 - Unauthenticated OS Command Injection via timeHandler.cgi timeZone Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2013-10049.
PoCs published by Metasploit, m-1-k-3, including Metasploit module exploits/linux/http/raidsonic_nas_ib5220_exec_noauth.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated command injection vulnerability in Raidsonic NAS devices via the timeHandler.cgi endpoint. It backdoors the device by adding a new user, modifying the inetd configuration, and spawning a telnet service for remote access.
Description
An OS command injection vulnerability exists in multiple Raidsonic NAS devices—specifically tested on IB-NAS5220 and IB-NAS4220—via the unauthenticated timeHandler.cgi endpoint exposed through the web interface. The CGI script fails to properly sanitize user-supplied input in the timeZone parameter of a POST request, allowing remote attackers to inject arbitrary shell commands.
Exploits (3)
This Metasploit module exploits an unauthenticated command injection vulnerability in Raidsonic NAS devices via the timeHandler.cgi endpoint. It backdoors the device by adding a new user, modifying the inetd configuration, and spawning a telnet service for remote access.
This exploit demonstrates an authentication bypass, stored XSS, and unauthenticated OS command injection in Raidsonic IB-NAS5220 / IB-NAS4220-B devices. The command injection is achieved via the `timeZone` parameter in a POST request to `/cgi/time/timeHandler.cgi`.
This Metasploit module exploits an unauthenticated command injection vulnerability in Raidsonic NAS devices via the timeHandler.cgi endpoint. It backdoors the device by adding a new user, modifying the inetd configuration, and spawning a telnet service for remote access.
References (5)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N