Synway SMG Gateway Management Software Command Injection Vulnerability in 9-12ping.php
Vulnerability
A command injection vulnerability has been identified in the Synway SMG Gateway Management Software, specifically in versions prior to 20250204. The issue resides in the 9-12ping.php file, where the 'retry' parameter can be manipulated to execute arbitrary commands on the server. This vulnerability can be exploited remotely without authentication, potentially leading to unauthorized command execution, disclosure of sensitive information, and disruption of service.
Impact
Exploitation of this vulnerability allows for arbitrary command execution on the affected system, which could be used to gain full control over the device. Additionally, such commands might be leveraged to access and extract sensitive information, such as configuration files or credentials. The vulnerability could also be exploited to disrupt normal service operations, potentially causing the device to crash or interfere with critical functions.
Reproduction
To reproduce this vulnerability, send an HTTP POST request to the '/en/9-12ping.php' endpoint. Include the 'retry' parameter in the request body, with a value that injects a command, such as 'echo 55294'. The request can be made using tools like curl or Postman, or through a script that automates the process.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
