Intelbras RX1500
cpe:2.3:h:intelbras:rx_1500:*:*:*:*:*:*:*, +1 more
- <= 2.2.17
An incorrect access control vulnerability has been identified in the Intelbras RX1500 Router, specifically in versions through 2.2.17. The issue resides in the FirmwareUpload and GetFirmwareValidation functions, which can be accessed without proper authorization. This vulnerability allows attackers to forge a firmware package, upload it to the router, and execute commands by exploiting the uploaded firmware.
Exploitation of this vulnerability could lead to unauthorized firmware uploads and execution of arbitrary commands on the router.
To reproduce this vulnerability, send a POST request to the router's HNAP1 interface with a forged firmware package. Include the 'SOAPAction' header to specify the 'FirmwareUpload' function. After uploading the malicious firmware, use the 'GetFirmwareValidation' function to trigger the execution of commands embedded in the uploaded firmware package.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.