vendor:
EKI-6340
by:
Facundo Pantaleo and Flavio Cangini
7,5
CVSS
HIGH
OS Command Injection [CWE-78]
78
CWE
Product Name: EKI-6340
Affected Version From: Advantech EKI-6340 V2.05
Affected Version To: Other versions may probably be affected too, but they were not checked.
Patch Exists: NO
Related CWE: CVE-2014-8387
CPE: Advantech/EKI-6340
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Advantech EKI-6340 Command Injection
The Advantech EKI-6340 series are wireless Mesh AP for outdoor deployment. With self-healing and self-forming capabilities, the wireless network is free from interruption even part of Mesh nodes failed. It's especially critical to infrastructures where wired solutions are hard to deploy. This Mesh network covers growing rich data demands such as video security, surveillance and entertainment. Advantech EKI-6340 series is vulnerable to a OS Command Injection, which can be exploited by remote attackers to execute arbitrary code and commands, by using a non privileged user against a vulnerable CGI file.
Mitigation:
Change the 'guest' user password (or delete the user in case is not used), Edit the fshttpd.conf and remove the line 'guest_allow=/cgi/ping.cgi', Check that the 'admin' user doesn't has the default password as well.