CVE-2019-12780
CRITICAL EXPLOITED IN THE WILDBelkin Crock-Pot Smart Slow Cooker with WeMo Firmware - Unauthenticated OS Command Injection via SmartDevURL Argument
Title source: llmExploitation Summary
CVE-2019-12780 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
EIP tracks 2 public exploits from researchers including Metasploit, phikshun, wvu, nstarke, including a Metasploit module exploits/linux/upnp/belkin_wemo_upnp_exec.
AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in Belkin Wemo UPnP devices via the SmartDevURL argument in the SetSmartDevInfo SOAP action. It supports both in-memory command execution and a Linux dropper for MIPSLE architectures.
Description
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.
Exploits (2)
This Metasploit module exploits a command injection vulnerability in Belkin Wemo UPnP devices via the SmartDevURL argument in the SetSmartDevInfo SOAP action. It supports both in-memory command execution and a Linux dropper for MIPSLE architectures.
This Metasploit module exploits a command injection vulnerability in Belkin Wemo UPnP devices via the SmartDevURL argument in the SetSmartDevInfo action. It supports both in-memory command execution and a Linux dropper for MIPSLE-based devices.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H