vendor:
dLAN 550 duo+ Starter Kit
by:
Stefan Petrushevski aka sm @zeroscience
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: dLAN 550 duo+ Starter Kit
Affected Version From: dLAN 500 AV Wireless+ 3.1.0-1 (i386)
Affected Version To: dLAN 500 AV Wireless+ 3.1.0-1 (i386)
Patch Exists: YES
Related CWE: N/A
CPE: h:devolo:dlan_500_av_wireless+
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux 2.6.31
2017
devolo dLAN 550 duo+ Starter Kit Remote Code Execution
The devolo firmware has what seems to be a 'hidden' services which can be enabled by authenticated attacker via the the htmlmgr CGI script. This allows the attacker to start services that are deprecated or discontinued and achieve remote arbitrary code execution with root privileges.
Mitigation:
The user should ensure that the configuration parameters are properly validated and sanitized before being used.