[0day-rubbish] Cambium cnMatrix EX3024F 6.2.1-r4 SSL CSR COMMON_NAME command injection to root RCE (7.2)
Cambium cnMatrix EX3024F 6.2.1-r4 SSL CSR field allows command injection to root RCE.
The 0day Rubbish Research Team publicly disclosed an OS command injection flaw in Cambium cnMatrix EX3024F firmware 6.2.1-r4. The COMMON_NAME field sent to POST /iss/specific/ssl_digitalcert.html is taken by HttpGetValuebyName and only percent-decoded before use. The issue is described as CWE-78, with CWE-20, CWE-250, and CWE-269 also cited, and is rated 7.2, leading to root remote code execution. No CVE or observed exploitation is stated.
- Command injection via COMMON_NAME on POST /iss/specific/ssl_digitalcert.html.
- Value is only percent-decoded before use (CWE-78 and CWE-20).
- Firmware 6.2.1-r4; disclosure rates impact 7.2 and root RCE.
- No CVE assigned and no in-the-wild exploitation reported.
Posted by disclosure via Fulldisclosure on Sep 26 0day Rubbish Research Team is publicly disclosing a vulnerability in the Cambium cnMatrix EX3024F managed switch, firmware 6.2.1-r4. Type: OS command injection (CWE-78, with CWE-20 bearing on it because percent-decoding is the only processing applied; CWE-250/CWE-269 bear on remediation priority). The COMMON_NAME form field submitted to POST /iss/specific/ssl_digitalcert.html is extracted by HttpGetValuebyName, percent-decoded by...
This source does not provide full text. Read it at seclists.org.