Record summary

CVE-2024-9166 has a selected CVSS score of 9.3 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Atemio AM 520 HD Full HD Satellite Receiver

Browse Atelmo / Atemio AM 520 HD Full HD Satellite Receiver

Default status: unaffected

CVE ListThrough TitanNit 2.01affected

Default status: unknown

CVE ListThrough titannit_2.01affected

Proofs of concept

1

Repository PoCs

GitHubAndrysqui/CVE-2024-9166Repository PoCby AndrysquiStars: 4Not analyzed4 files

10.3 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALTitanNit Web Control 2.01/Atemio 7600 - Remote Code Execution

The device contains a command injection caused by the 'getcommand' query in the application, letting unauthorized attackers execute system commands with root privileges, exploit requires attacker to send crafted requests.

Impact

Unauthenticated attackers can execute arbitrary system commands with root privileges through command injection in the getcommand query parameter, achieving complete control of the TitanNit Web Control device and potentially pivoting to connected industrial control systems.

Remediation

Apply security patches from TitanNit for Web Control 2.01 and Atemio 7600 to address the command injection vulnerability in the getcommand query parameter.

WeaknessesCWE-78
AuthorsDhiyaneshDk
Template tagscvecve2024titanitweb-controloastrceicsvuln
FOFA: title="TitanNit Web Control"

Source: ProjectDiscovery

References

2