The vulnerability has been used in Satori attacks against Huawei's router model HG532. The most targeted countries include the United States, Italy, Germany, and Egypt.
Satori botnet, Mirai malware
Vulnerable component: Huawei HG532
CVSSv3 score: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:H/RL:W/RC:C
CWE-ID: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
The vulnerability allows a remote attacker with administrator privileges to perform command injection attack on the target system.
The weakness exists due to the implementation of the TR-064 (technical report standard), an application layer protocol for remote management, in the Huawei devices was exposed on the public Internet through Universal Plug and Play (UPnP) protocol at port 37215. A remote attacker can inject shell meta-characters тАЬ$()тАЭ in the NewStatusURL and NewDownloadURL, inject arbitrary commands and execute arbitrary code.
Successful exploitation of the vulnerability allows to download and execute the malicious payload on the Huawei routers and upload Satori botnet that may result in system compromise.
Note: the vulnerability is being actively exploited.
Latest references in media:
- BrickerBot mod_plaintext Analysis [2017-12-19 01:00:00]
- A New Internet of Things Botnet Originated on 'Grand Theft Auto' Servers [2018-02-15 19:11:24]
- A New Internet of Things Botnet Originated on 'Grand Theft Auto' Servers [2018-02-15 19:00:22]
- JenX botnet leverages Grand Theft Auto videogame community to infect devices [2018-02-03 13:10:13]
- JenX Botnet Has Grand Theft Auto Hook [2018-02-02 19:40:07]
- Adobe Flash Player Zero-Day Spotted in the Wild [2018-02-01 21:50:41]
- Satori Author Linked to New Mirai Variant Masuta [2018-01-24 01:00:06]
- Satori Botnet Is Now Attacking Ethereum Mining Rigs [2018-01-17 11:12:55]
- Mirai┬аOkiru botnet targets for first time ever in the history ARC-based IoT devices [2018-01-15 00:02:12]
- Satori IoT botnet malware code given away for Christmas | ZDNet [2018-01-03 11:30:04]
- Security Affairs newsletter Round 143 тАУ News of the week [2017-12-31 13:40:06]
- Huawei router exploit (CVE-2017-17215) involved in Satori and Brickerbot was leaked online [2017-12-29 15:30:17]
- Code Used in Zero Day Huawei Router Attack Made Public [2017-12-28 20:10:11]
- Satori/Okiku IoT Botnet Recruits Hundreds of Thousands of Huawei Routers for DDoS Army [2017-12-23 09:50:03]
- Satori is the latest Mirai botnet variant that is targeting Huawei┬аHG532 home routers [2017-12-23 08:10:10]
- Huawei Router Vulnerability Used to Spread Mirai Variant [2017-12-23 00:10:12]
- Mirai Variant "Satori" Targets Huawei Routers [2017-12-22 17:30:22]
- Amateur Hacker Behind Satori Botnet [2017-12-22 11:14:22]
Vulnerability scanning SaaS service is online 3-rd generation vulnerability scanner with scheduled assessments and vulnerability subscription. You can use service to check security of your network perimeter.