Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-30167. PoCs published by rizzziom, RIZZZIOM.
AI-analyzed exploit summary This Go-based exploit demonstrates an authenticated command injection vulnerability in Atlona AT-OME-RX21 devices. It sends a crafted JSON payload to the `/cgi-bin/time.cgi` endpoint, injecting a command that exfiltrates output via a curl POST request to an attacker-controlled server.
Description
/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName parameter.
Exploits (2)
This Go-based exploit demonstrates an authenticated command injection vulnerability in Atlona AT-OME-RX21 devices. It sends a crafted JSON payload to the `/cgi-bin/time.cgi` endpoint, injecting a command that exfiltrates output via a curl POST request to an attacker-controlled server.
This repository contains a functional Go-based exploit for CVE-2024-30167, an authenticated command injection vulnerability in Atlona AT-OME-RX21 firmware <= 1.5.1. The exploit leverages the time configuration interface to execute arbitrary commands as root via crafted JSON payloads.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L