Telesquare SKT LTE Router SDT-CS3B1...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary We introduce SDT-CS3B1 LTE router which is a SKT 3G and 4G LTE wireless communication based LTE router product. ### Description WebDAV is enabled with directory listing and dangerous HTTP methods allowed: PROPFIND, DELETE, MKCOL, PUT, MOVE, COPY, PROPPATCH, LOCK and UNLOCK. The HTTP PUT method is normally used to upload data that is saved on the server at a user-supplied URL. An attacker can place arbitrary, and potentially malicious, content into the application. Depending on the server's configuration, this may lead to compromise of the server (by uploading server-executable code), or other attacks. The other methods can be used to delete/move/overwrite/create files and cause denial of service scenarios and/or phishing attacks. ### Vendor Telesquare Co., Ltd. - http://www.telesquare.co.kr ### Affected Version * FwVer: SDT-CS3B1, sw version 1.2.0 * LteVer: ML300S5XEA41_090 1 0.1.0 * Modem model: PM-L300S ### Tested On * lighttpd/1.4.20 ### PoC ``` PUT /ssi.shtml...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息