> CVE-2022-27226: CSRF to RCE in iRZ Mobile Routers through 2022-03-16
[DATE: 18/03/2022 23:00]
[LANGUAGE: EN]
Credits Vulnerability Discovery
John
Chris Mack
Exploit Development
Stephen Chavez
Robert Willis
Identification Default credentials were discovered on an iRZ Mobile Router login page. Utilizing root:root gave us access to the administrative functionality for the device. Having administrative access allows for various manipulation. Any setting that can be modified by an administrator was accessible, but the function that caught specific interest was the “Crontabs” feature in the services tab.
Exploiting crontabs for Post Authenticated RCE The first exploit that was identified was the ability to achieve remote code execution via the router’s native crontabs functionality.