CVE-2019-14931
CRITICAL EXPLOITED IN THE WILDMitsubishielectric Smartrtu Firmware < 2.02 - OS Command Injection
Title source: ruleExploitation Summary
CVE-2019-14931 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including xerubus.
AI-analyzed exploit summary This exploit leverages an unauthenticated OS command injection vulnerability in Mitsubishi Electric smartRTU and INEA ME-RTU devices. It sends a malicious payload via a POST request to execute a bind shell using netcat, allowing remote command execution.
Description
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.
Exploits (1)
This exploit leverages an unauthenticated OS command injection vulnerability in Mitsubishi Electric smartRTU and INEA ME-RTU devices. It sends a malicious payload via a POST request to execute a bind shell using netcat, allowing remote command execution.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H