Remote Command Injection in Belkin N300 Firmware
CVE-2022-30105
9.8CRITICAL
Key Information:
- Vendor
Belkin
- Status
- Vendor
- CVE Published:
- 18 May 2022
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2022-30105?
The Belkin N300 Firmware 1.00.08 contains multiple remote command injection vulnerabilities in its web interface located at /setting_hidden.asp. These vulnerabilities arise from improper sanitization of parameters in the web form, allowing attackers to send specially crafted POST requests that can execute arbitrary OS commands with root privileges. Given that the web interface and associated processes operate as root, successful exploitation could lead to complete device control, potentially compromising network security.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
