CVE-2020-24217
CRITICAL EXPLOITEDHiSilicon Video Encoder Firmware - Unauthenticated Arbitrary Code Execution via Firmware Upload
Title source: llmExploitation Summary
CVE-2020-24217 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Alexei Kojenov.
AI-analyzed exploit summary This exploit leverages an unauthenticated firmware upload vulnerability in HiSilicon-based video encoders to achieve remote command execution. It creates a malicious RAR archive containing a command, uploads it via HTTP POST, and triggers execution on the target device.
Description
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution.
Exploits (2)
This exploit leverages an unauthenticated firmware upload vulnerability in HiSilicon-based video encoders to achieve remote command execution. It creates a malicious RAR archive containing a command, uploads it via HTTP POST, and triggers execution on the target device.
This exploit leverages an unauthenticated command injection vulnerability in HiSilicon-based video encoders by crafting a malicious filename in a multipart form upload. The command is injected via the 'upgrade' parameter and executed on the target device.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H