Description
Some Seagate Business NAS devices are vulnerable to command execution via a local file include vulnerability hidden in the language parameter of the CodeIgniter session cookie. The vulnerability manifests in the way the language files are included in the code on the login page, and hence is open to attack from users without the need for authentication. The cookie can be easily decrypted using a known static encryption key and re-encrypted once the PHP object string has been modified.
This module has been tested on the STBN300 device.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/seagate/nas_php_exec_noauthmsf undefined(nas_php_exec_noauth) > show actions ...actions...msf undefined(nas_php_exec_noauth) > set ACTION < action-name >msf undefined(nas_php_exec_noauth) > show options ...show and set options...msf undefined(nas_php_exec_noauth) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub