Multiple OS command injection vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an authenticated remote attacker to execute arbitrary OS commands via various endpoint parameters.
The vulnerability (CWE-77 — Improper Neutralization of Special Elements used in a Command) consists of insufficient input data validation in multiple parameters of various endpoints of the device interface. An authenticated attacker can submit crafted requests containing malicious system commands, which are then executed directly by the device's operating system. The vulnerability affects firmware version 3.3.23.6.9 and earlier.
An attacker with access to an account (even with limited privileges) can execute arbitrary commands at the operating system level of the device, which may lead to complete device takeover, breach of data confidentiality and integrity, and disruption of its availability. Due to the industrial nature of the devices, the consequences may also include OT/ICS systems and networks connected through these devices.
Apply patches available from the manufacturer according to the references. Additionally, it is recommended to restrict access to the device management interface exclusively to trusted IP addresses, segment the OT/ICS network, and monitor unauthorized login attempts. Detailed recommendations are contained in the ICS-CERT advisory: ICSA-24-214-08.
Vonets VAR1200-H, VAR1200-L and VAR600-H (firmware) — software version 3.3.23.6.9 and earlier
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XVonets Vap11ac
HWVonetsall versionsVonets Vap11ac Firmware
OSVonets≤ 3.3.23.6.9Vonets Vap11g
HWVonetsall versionsVonets Vap11g 300
HWVonetsall versionsVonets Vap11g 300 Firmware
OSVonets≤ 3.3.23.6.9Vonets Vap11g 500
HWVonetsall versionsVonets Vap11g 500 Firmware
OSVonets≤ 3.3.23.6.9Vonets Vap11g 500s
HWVonetsall versionsVonets Vap11g 500s Firmware
OSVonets≤ 3.3.23.6.9Vonets Vap11g Firmware
OSVonets≤ 3.3.23.6.9Vonets Vap11n 300
HWVonetsall versionsVonets Vap11n 300 Firmware
OSVonets≤ 3.3.23.6.9Vonets Vap11s
HWVonetsall versionsVonets Vap11s 5g
HWVonetsall versionsVonets Vap11s 5g Firmware
OSVonets≤ 3.3.23.6.9Vonets Vap11s Firmware
OSVonets≤ 3.3.23.6.9Vonets Var11n 300
HWVonetsall versionsVonets Var11n 300 Firmware
OSVonets≤ 3.3.23.6.9Vonets Var1200 H
HWVonetsall versionsVonets Var1200 H Firmware
OSVonets≤ 3.3.23.6.9Vonets Var1200 L
HWVonetsall versionsVonets Var1200 L Firmware
OSVonets≤ 3.3.23.6.9Vonets Var600 H
HWVonetsall versionsVonets Var600 H Firmware
OSVonets≤ 3.3.23.6.9Vonets Vbg1200
HWVonetsall versionsVonets Vbg1200 Firmware
OSVonets≤ 3.3.23.6.9Vonets Vga 1000
HWVonetsall versionsVonets Vga 1000 Firmware
OSVonets≤ 3.3.23.6.9
Related vulnerabilities
Odmowa usługi w urządzeniach Vonets WiFi Bridge przez wadliwy HTTP request
Stack-based buffer overflow RCE w urządzeniach Vonets WiFi Bridge
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemComman...
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged...
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebs...