HTTP: Belkin WeMo Router UPnP Arbitrary Firmware Upload Attempt

This signature detects remote firmware upload in Belkin Wemo routers. An unspecified flaw in the UPnP implementation may allow an attacker to upload arbitrary firmware and gain shell access and modify the device.

Extended Description

Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.

References

CVE: CVE-2013-2748

Short Name
HTTP:MISC:BELKIN-ROUTER-UPLOAD
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Arbitrary Attempt Belkin CVE-2013-2748 Firmware Router UPnP Upload WeMo
Release Date
04/17/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
CVSS Score

7.5

Found a potential security threat?