Unsafe firewall includes allowing for remote code execution on Inteno's IOPSYS devices

In Inteno's IOPSYS devices, and very possibly other devices running firewall3 (which is included by default on most OpenWRT-based firmwares), it is possible for an authenticated attacker to abuse firewall includes to remotely execute any binary or script as root. A proof-of-concept exploit can be found at the end of the post. This vulnerability has been assigned the CVE ID: CVE-2018-20487.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论