HTTP: Eir D1000 DSL Modem NewNTPServer Command Injection

This signature detects attempts to exploit a known vulnerability against Eir D1000 DSL Modem NewNTPServer. Successful attack could lead to Command Injection.

Extended Description

The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and using the NewNTPServer feature.

Short Name
HTTP:CVE-2016-10372-CMD-IN
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2016-10372 Command D1000 DSL Eir Injection Modem NewNTPServer
Release Date
02/04/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3377
False Positive
Unknown
CVSS Score

10.0

Found a potential security threat?