vendor:
FlexAir Access Control
by:
LiquidWorm
8.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: FlexAir Access Control
Affected Version From: 2.3.38
Affected Version To: 2.4.9api3
Patch Exists: YES
Related CWE: CVE-2019-9189
CPE: a:computrols:flexair_access_control
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: NA
2019
FlexAir Access Control 2.4.9api3 – Remote Code Execution
A vulnerability exists in FlexAir Access Control (Prima Systems) Firmware version: <= 2.3.38, which allows an attacker to execute arbitrary code with root privileges. This is achieved by sending a specially crafted payload to the server, which is then executed. The payload is sent via a POST request to the /bin/sysfcgi.fx endpoint, and the output is stored in the /www/pages/app/images/logos/output.txt file.
Mitigation:
Upgrade to the latest version of FlexAir Access Control (Prima Systems) Firmware.