AMTT Hotel Broadband Operation System Command Injection Vulnerability in Network Port Setup Management

Vulnerability

A critical OS command injection vulnerability has been identified in AMTT Hotel Broadband Operation System version 1.0. The issue arises in the 'popen' function within the file '/manager/network/port_setup.php'. Manipulating the 'SwitchVersion', 'SwitchWrite', 'SwitchIP', 'SwitchIndex', and 'SwitchState' parameters allows for arbitrary command execution on the server. This vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution on the server where the application is running.

Reproduction

To reproduce this vulnerability, send a GET request to '/manager/network/port_setup.php' with the 'SwitchIP', 'SwitchPort', 'SwitchIndex', and 'SwitchVersion' parameters. The 'SwitchVersion' parameter should be crafted to include the desired command, such as 'whoami' redirected to a file, like '1.txt'. After the request is processed, the output of the executed command can be retrieved from the same directory where the command was executed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.