HTTP: Advantech R-SeeNet device_position device_id SQL Injection
This signature detects attempts to exploit a known vulnerability against Advantech R-SeeNet. A successful attack can lead to command injection and arbitrary code execution.
Extended Description
The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.
Affected Products
Advantech r-seenet
References
CVE: CVE-2021-21924
URL: https://ep.advantech-bb.cz/support/router-models/download/239/sa-2020-01-01-r-seenet-2-4-10-vulnerability-en.pdf https://icr.advantech.cz/support/router-models/download/239/sa-2021-03-r-seenet-vulnerabilities.pdf https://talosintelligence.com/vulnerability_reports/TALOS-2021-1366
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Advantech
6.5
5.0