该基于 Web 的管理界面使用经过修改的 uhttpd 服务器,并配有 CGI Shell 脚本。HTTP 基本认证中的用户名直接取自 Authorization 头,未经过任何过滤或 sanitization 处理,随后被插入到通过 system() 函数执行的 Shell 命令字符串中。攻击者可以通过提交一个包含特殊 Shell 元字符的精心构造的用户名,从而突破命令上下文限制,在未认证的状态下(只要具备对该设备的网络访问权限)以 root 权限执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Weidmueller Interface | IE-SR-2TX-WL | 1.52< 1.57 |
affected |
| Weidmueller Interface | IE-SR-2TX-WL-4G-EU | 1.67< 1.74 |
affected |
| Weidmueller Interface | IE-SR-2TX-WL-4G-US-V | 1.67< 1.74 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Weidmueller Interface | IE-SR-2TX-WL | 1.52 ~ 1.57 | - |
|
| Weidmueller Interface | IE-SR-2TX-WL-4G-EU | 1.67 ~ 1.74 | - |
|
| Weidmueller Interface | IE-SR-2TX-WL-4G-US-V | 1.67 ~ 1.74 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet