PLANEX CS-QR20 Command Execution

PLANEX CS-QR20 suffers from a remote command execution vulnerability due to a hidden management page existing.

Reserved CVE: CVE-2017-12576

# Description
A hidden and undocumented management page allows an attacker to execute arbitrary code on the device when the user is authenticated.

# Vulnerability Type
Insecure Permissions

# Affected Product Code Base
Firmware ver 1.30

# Affected Component]
Web management UI

# Attack Type

# Attack Vectors
Connect hidden and undocumented management page and execute arbitrary code after authenticated

# Discoverer
Kenney Lu (Trend Micro)

# Vulnerability Detail
An admin page was used for debugging purpose, once you login and access the page directly (/admin/system_command.asp), you can execute any command.

