CVE-2021-42165
HIGHMitraStar GPT-2541GNAC-N1 Firmware - Authenticated OS Command Injection via DeviceInfo Path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-42165. PoCs published by Leonardo Nicolas Servalli.
AI-analyzed exploit summary This exploit leverages a command injection vulnerability in the Mitrastar GPT-2541GNAC-N1 router's restricted shell. By appending '&&/bin/bash' to the 'deviceinfo show file' command, an attacker can spawn a root shell due to improper handling of special characters.
Description
MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".
Exploits (1)
This exploit leverages a command injection vulnerability in the Mitrastar GPT-2541GNAC-N1 router's restricted shell. By appending '&&/bin/bash' to the 'deviceinfo show file' command, an attacker can spawn a root shell due to improper handling of special characters.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H