Hanwha Techwin Smart Security Manager ActiveMQ CORS Bypass Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4. This vulnerability arises from improper restrictions on the PUT method in the bundled Apache ActiveMQ instance, which is accessible on port 8161. Exploitation involves a Cross-Origin Resource Sharing (CORS) bypass, allowing an attacker to upload malicious files to the web server via JavaScript, ultimately executing arbitrary code with SYSTEM privileges. This issue circumvents server-side mitigations from previous advisories by shifting the exploitation to the client-side.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system with SYSTEM privileges.

Reproduction

The vulnerability can be reproduced by uploading a crafted file through the ActiveMQ PUT method, exploiting a CORS bypass. This can be done by first creating a Cross-Origin request that bypasses the same-origin policy, and then using JavaScript to upload a file to the server via an XMLHttpRequest. The uploaded file can be a script that, once executed, provides a reverse shell or similar payload, effectively compromising the system.

Remediation

Users are advised to update to Hanwha Techwin Smart Security Manager version 1.41 or later.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
7.5
exploitability
7.4
remediation
7.7
relevance
0.3
threat
6.5
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.