CRLF Injection - Sercomm VD625

Published on 10 Jan 2022
Vulnerability

Description

Sercomm AGCOMBO VD625 Smart Modems with firmware version AGSOT_2.1.0 are vulnerable to CRLF Injection via the Content-Disposition header

The device has a web interface for management which is exposed to the public, and it is easy to send a modified http request to the web server by simply adding a.txt or other sort of extension to the GET request’s url, which causes the device to believe it is a download request. The system then inserts the contents of the url we entered into the header field “Content-Disposition,” and attempts to download the file.

Because this header field is not fully sanitised, it is possible to force the header to wrap by inserting a new line and then inserting further header fields as desired in the http response using the CRLF technique.

Recommendations

  • Update Sercomm firmware to the latest version.
Anandhu K A
Written by
Lead Engineer

With a profound understanding of product development, Anandhu plays a pivotal role in crafting cutting-edge solutions that cater to the evolving security needs of digital applications. His expertise, deeply rooted in both engineering and security, makes him an essential component of Beagle Security's mission

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo