[0day-rubbish] Lantronix EDS3000PR 3.2.0.0R2 two vulnerabilities
disclosure via Fulldisclosure ·
0day Rubbish Research Team is publicly disclosing two vulnerabilities in Lantronix EDS3000PR 3.2.0.0R2. Vulnerability 1 — Authenticated command injection to root RCE in FsUnmount (CVSS 8.8, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, CWE-78) Lantronix EDS3000PR is an industrial serial device server (CII/OT). Its FsUnmount page handler validates a user-supplied path against a character bitmask that rejects most shell metacharacters but allows single quotes and newlines, then executes /sbin/ltrx_usb_umount '/ltrx_user<path>' via /bin/sh -c. A newline breaks out of the single-quoted command and the injected command executes as root. Verified with a root-owned marker in a qemu-arm chroot using the real rootfs /bin/sh. Authentication: authenticated (requires valid session) Vulnerability 2 — Authenticated command injection to root RCE in SSL certificate import and diagnostics (CVSS 8.8, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, CWE-78) On the same Lantronix EDS3000PR device, the SSL certificate upload handler builds openssl rsa|dsa|ec|pkcs12 -passin pass:%s commands from the attacker-controlled certificate password and executes them via system(); the diagnostics handler builds ping and traceroute commands from the attacker-controlled host field the same way. No shell-character sanitization exists. An authenticated admin submits a semicolon or command-substitution payload in the password or host field; the injected command executes as root. Verified with root markers for 5/5 SSL vectors and 3/3 diagnostics vectors. Authentication: authenticated (requires valid session) Full technical analyses and reproducible proofs-of-concept: https://0day-rubbish.com/blog/lantronix-eds3000pr-fsunmount-command-injection https://0day-rubbish.com/blog/lantronix-eds3000pr-passin-pass-command-injection Project archive (ongoing disclosure series): https://github.com/Exploit-Garbage/0day-Rubbish Vendor has been notified. CVE IDs are pending. -- 0day Rubbish Research Team disclosure () 0day-rubbish com https://0day-rubbish.com _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/