ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds D-Link DIR-820 Router, DrayTek Multiple Vigor Router, Motion Spell GPAC, SAP Commerce Cloud bugs to its Known Exploited Vulnerabilities catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0344
Unauthenticated Deserialization RCE in SAP Commerce Cloud (virtualjdbc)

SAP Commerce Cloud releases 6.4, 6.5, 6.6, 6.7, 1808, 1811 and 1905 use unsafe deserialization of untrusted data in the virtualjdbc extension, letting attackers who can reach that component over the network inject and execute arbitrary code. No authentication or user interaction is required, which is reflected in the critical 9.8 CVSS 3.1 score. Successful exploitation yields code execution under the 'Hybris' user account on the target machine, enough to compromise the commerce platform and pivot further into the environment. Any organization running one of the listed SAP Commerce versions with the virtualjdbc extension deployed is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-30, confirming exploitation in the wild, although no public proof-of-concept is known.

Do: Upgrade affected SAP Commerce releases (6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905) to the patched patch levels per SAP's security advisory for CVE-2019-0344, or move to a current supported release. If patching is delayed, restrict network access to the virtualjdbc extension or remove it if unused, and verify whether it is exposed to the internet. Given the KEV listing, review logs for suspicious requests to the virtualjdbc endpoint and unexpected processes running as the 'Hybris' user; federal agencies must apply vendor mitigations or discontinue use of the product.

9.87% KEV
  • SAP Commerce Cloud (virtualjdbc extension) 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905
moderatelikely in the low thousands of installations; internet-exposed subset unknown
CVE-2020-15415
Unauthenticated OS Command Injection in DrayTek Vigor3900/2960/300B Routers

DrayTek Vigor3900, Vigor2960, and Vigor300B routers running firmware before 1.5.1 contain an unauthenticated OS command injection flaw (CWE-78) in the cvmcfgupload handler of the web management interface (cgi-bin/mainfunction.cgi/cvmcfgupload), distinct from CVE-2020-14472. A remote attacker sends an upload request using the text/x-python-script content type with shell metacharacters embedded in the filename, which the device passes to a shell without sanitization, achieving arbitrary command execution. Because no credentials or user interaction are required, an internet-exposed management interface can be fully compromised, giving the attacker control of the router and a foothold into the network behind it. Any organization or site running one of these three Vigor models on pre-1.5.1 firmware is affected, especially where the web UI is reachable from the internet. Exploitation is confirmed: a public proof-of-concept exists, EPSS rates 30-day exploitation probability at 84.5% (100th percentile), CISA added the bug to the Known Exploited Vulnerabilities catalog on 2024-09-30, and recent reporting ties Mirai V3G4 botnet activity to campaigns exploiting a batch of 13 IoT flaws.

Do: Upgrade Vigor3900, Vigor2960, and Vigor300B firmware to version 1.5.1 or later per DrayTek's instructions, consistent with the CISA KEV required action (apply vendor mitigations or discontinue use). Until patched, do not expose the web management interface to the internet (restrict to trusted management IPs or VPN access) and hunt for compromise indicators such as unexpected processes, altered configurations, or Mirai-like scanning traffic. Check access logs for requests to /cgi-bin/mainfunction.cgi/cvmcfgupload using the text/x-python-script content type with metacharacters in the filename.

9.884% KEV PoC
  • DrayTek Vigor3900 firmware before 1.5.1
  • DrayTek Vigor2960 firmware before 1.5.1
  • DrayTek Vigor300B firmware before 1.5.1
large≈100,000 internet-exposed Vigor3900/2960/300B devices (order-of-magnitude estimate)
CVE-2021-4043
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.

NVD description · AI analysis pending
5.55% PoC
  • gpac gpac
  • gpac debian linux
CVE-2023-25280
Unauthenticated OS Command Injection in D-Link DIR-820 Router (CVE-2023-25280)

CVE-2023-25280 is an unauthenticated OS command injection flaw (CWE-78) in D-Link DIR-820 router firmware DIR820LA1_FW105B03, located in the ping.ccp web interface. A remote attacker with no credentials can send a crafted ping_addr parameter to ping.ccp, causing arbitrary operating-system commands to execute on the router. Successful exploitation escalates privileges to root, giving an attacker full control of the device for use as a botnet node or a foothold into the connected network. Users running the affected D-Link DIR-820 hardware are exposed, and because the product is end-of-life/end-of-service, fixes are not expected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-30, EPSS puts the 30-day exploitation probability at 97.9% (100th percentile), a public proof-of-concept is available, and active botnet campaigns such as RondoDox and Mirai-style campaigns are targeting flaws in this class of IoT devices.

Do: Per CISA's KEV required action, discontinue use of this end-of-life/end-of-service product — retire or replace the DIR-820, since no patched firmware is expected. If replacement must be delayed, restrict the router's web interface so it is not reachable from the WAN, disable remote management, and monitor for signs of botnet infection such as unusual outbound traffic. When inventorying, verify installed firmware version (affected build: DIR820LA1_FW105B03).

9.898% KEV PoC
  • D-Link DIR-820 (DIR-820L) router DIR8LA1_FW105B03 firmware (the version named in the advisory; no other version ranges were specified)
moderatelikely tens of thousands of internet-exposed units (estimated; no authoritative public scan count for this single end-of-life model)
Full article276 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds D-Link DIR-820 Router, DrayTek Multiple Vigor Router, Motion Spell GPAC, SAP Commerce Cloud bugs to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall SonicOS, ImageMagick and Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these vulnerabilities:

  • CVE-2023-25280 D-Link DIR-820 Router OS Command Injection Vulnerability
  • CVE-2020-15415 DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
  • CVE-2021-4043 Motion Spell GPAC Null Pointer Dereference Vulnerability
  • CVE-2019-0344 SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

CVE-2023-25280 is an OS command injection vulnerability in D-Link DIR-820 router. Since March 2023, Unit 42 researchers have observed a variant of the Mirai botnet spreading by targeting tens of flaws in D-Link, Zyxel, and Netgear devices, including CVE-2023-25280.

CVE-2020-15415 is an OS command injection vulnerability in DrayTek Multiple Vigor Routers. Since the second half of 2022, a variant of the Mirai bot, tracked as V3G4, targeted IoT devices by exploiting tens of flaws, including CVE-2020-15415.

CVE-2019-0344 is a deserialization of untrusted data vulnerability. SAP Commerce Cloud

CVE-2021-4043 is a null pointer dereference vulnerability in Motion Spell GPAC.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by October 21, 2024.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/169189/hacking/u-s-cisa-adds-d-link-dir-820-router-draytek-multiple-vigor-router-motion-spell-gpac-sap-commerce-cloud-bugs-to-its-known-exploited-vulnerabilities-catalog.html