CVE-2019-7276
CRITICAL EXPLOITED IN THE WILD NUCLEIOptergy Enterprise and Proton < 2.3.0a - Remote Root Code Execution via Backdoor Console
Title source: llmExploitation Summary
CVE-2019-7276 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
EIP tracks 2 public exploits from researchers including LiquidWorm, including a Metasploit module exploits/linux/http/optergy_bms_backdoor_rce_cve_2019_7276.
A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit leverages an unauthenticated backdoor in Optergy BMS to execute arbitrary commands as root by bypassing authentication via a challenge-response mechanism. It sends a crafted POST request with a computed SHA1 and MD5 hash to achieve remote code execution.
Description
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
Exploits (2)
This exploit leverages an unauthenticated backdoor in Optergy BMS to execute arbitrary commands as root by bypassing authentication via a challenge-response mechanism. It sends a crafted POST request with a computed SHA1 and MD5 hash to achieve remote code execution.
This Metasploit module exploits an undocumented backdoor in Optergy Proton and Enterprise BMS (CVE-2019-7276) by leveraging a challenge-response mechanism to execute arbitrary commands as root via sudo. The exploit interacts with the Console.jsp backdoor script to achieve remote code execution.
Nuclei Templates (1)
html:"Optergy"
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H