vendor:
MSNSwitch Firmware
by:
Eli Fulkerson
9.8
CVSS
CRITICAL
Remote Code Execution (RCE)
78
CWE
Product Name: MSNSwitch Firmware
Affected Version From: MNT.2408
Affected Version To: MNT.2408
Patch Exists: YES
Related CWE: CVE-2022-32429
CPE: a:msnswitch:msnswitch_firmware:mnt.2408
Tags: config,dump,packetstorm,cve,cve2022,msmswitch,unauth,switch
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Nuclei References:
https://packetstormsecurity.com/files/169819/MSNSwitch-Firmware-MNT.2408-Remote-Code-Execution.html, https://elifulkerson.com/CVE-2022-32429/, https://nvd.nist.gov/vuln/detail/CVE-2022-32429, http://packetstormsecurity.com/files/169819/MSNSwitch-Firmware-MNT.2408-Remote-Code-Execution.html
Nuclei Metadata: {'max-request': 1, 'shodan-query': 'http.favicon.hash:-2073748627 || http.favicon.hash:-1721140132', 'verified': True, 'vendor': 'megatech', 'product': 'msnswitch_firmware'}
Platforms Tested: MNT.2408 firmware
2022
MSNSwitch Firmware MNT.2408 – Remote Code Exectuion (RCE)
POC for unauthenticated configuration dump, authenticated RCE on msnswitch firmware 2408. Configuration dump only requires HTTP access. Full RCE requires you to be on the same subnet as the device.
Mitigation:
Ensure that authentication is required for all administrative functions and that all users have unique, strong passwords.