vendor:
RSVA11001
by:
7.5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: RSVA11001
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
Exploit on Rosewill RSVA11001
The exploit allows an attacker to gain a root shell on the Rosewill RSVA11001 device by setting the NTP host to a command that opens a reverse shell on port 5555. The exploit takes advantage of a vulnerability in the 'hi_dvr' executable that controls the device's interface. The default startup command runs the exploit on startup and once a day, resulting in a delay if the exploit is remote-only. The authentication on the command port is bypassed by replaying packets from a capture session.
Mitigation:
To mitigate this vulnerability, it is recommended to update the firmware of the Rosewill RSVA11001 device to a patched version that fixes the vulnerability. Additionally, restricting network access to the command port can help prevent unauthorized access.