PT-2018-1032 · Ravpower · Ravpower Filehub

Daniele Linguaglossa

+1

·

Published

2018-01-24

·

Updated

2018-02-12

·

CVE-2018-5997

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RAVPower Filehub version 2.000.056
Description The issue is related to the HTTP Server in the RAVPower Filehub, where an unrestricted upload feature and a path traversal vulnerability allow uploading a file on the filesystem with root privileges, leading to remote code execution as root. The vulnerability exists due to insufficient restrictions on the directory path name and a lack of limitations on file uploads. This can be exploited by a remote attacker to execute arbitrary code with root privileges.
Recommendations For RAVPower Filehub version 2.000.056, consider restricting access to the HTTP Server until a patch is available. As a temporary workaround, disabling the upload feature can help minimize the risk of exploitation. Additionally, limiting directory access and implementing proper path validation can also reduce the vulnerability to remote code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00331
CVE-2018-5997

Affected Products

Ravpower Filehub