CVE-2024-9166
OS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite Receiver
Record summary
CVE-2024-9166 has a selected CVSS score of 9.3 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Atemio AM 520 HD Full HD Satellite ReceiverBrowse Atelmo / Atemio AM 520 HD Full HD Satellite ReceiverDefault status: unaffected | CVE List | Through TitanNit 2.01 | affected |
atemio_am_520_hd_firmwareBrowse atelmo / atemio_am_520_hd_firmwareDefault status: unknown | CVE List | Through titannit_2.01 | affected |
Proofs of concept
1Repository PoCs
GitHubAndrysqui/CVE-2024-9166Repository PoCby AndrysquiStars: 4Not analyzed4 files
Nuclei templates
1ProjectDiscoveryCRITICALTitanNit Web Control 2.01/Atemio 7600 - Remote Code Execution
The device contains a command injection caused by the 'getcommand' query in the application, letting unauthorized attackers execute system commands with root privileges, exploit requires attacker to send crafted requests.
Impact
Unauthenticated attackers can execute arbitrary system commands with root privileges through command injection in the getcommand query parameter, achieving complete control of the TitanNit Web Control device and potentially pivoting to connected industrial control systems.
Remediation
Apply security patches from TitanNit for Web Control 2.01 and Atemio 7600 to address the command injection vulnerability in the getcommand query parameter.
Source: ProjectDiscovery