CVE-2022-32429
CRITICAL NUCLEIMega System Technologies MSNSwitch MNT.2408 - Unauthenticated Remote Code Execution via ExportSettings.sh
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-32429. PoCs published by Eli Fulkerson. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates unauthenticated configuration dump and authenticated RCE in MSNSwitch Firmware MNT.2408 via command injection in the firmware upgrade mechanism. It leverages a CSRF token and command injection to execute arbitrary commands, sending results to a listener.
Description
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.
Exploits (1)
This exploit demonstrates unauthenticated configuration dump and authenticated RCE in MSNSwitch Firmware MNT.2408 via command injection in the firmware upgrade mechanism. It leverages a CSRF token and command injection to execute arbitrary commands, sending results to a listener.
Nuclei Templates (1)
http.favicon.hash:-2073748627 || http.favicon.hash:-1721140132
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H