CVE-2018-20841
CRITICAL EXPLOITED IN THE WILDHooToo TripMate Titan HT-TM05 Firmware 2.000.022 and 2.000.082 - Remote Command Execution via mac Parameter
Title source: llmExploitation Summary
CVE-2018-20841 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including Andrei Manole.
AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in Hotoo HT-05 devices by sending a crafted HTTP request to execute a telnetd backdoor. It then connects to the opened port to establish a remote shell.
Description
HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request.
Exploits (1)
This Metasploit module exploits a command injection vulnerability in Hotoo HT-05 devices by sending a crafted HTTP request to execute a telnetd backdoor. It then connects to the opened port to establish a remote shell.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H