.. / CVE-2021-40661

Exploit for IND780 - Local File Inclusion (CVE-2021-40661)

Description:

IND780 Advanced Weighing Terminals Build 8.0.07 March 19, 2018 (SS Label ‘IND780_8.0.07’), Version 7.2.10 June 18, 2012 (SS Label ‘IND780_7.2.10’) is vulnerable to unauthenticated local file inclusion. It is possible to traverse the folders of the affected host by providing a relative path to the ‘webpage’ parameter in AutoCE.ini. This could allow a remote attacker to access additional files on the affected system.

Nuclei Template

View the template here CVE-2021-40661.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-40661.yaml
Copy

References:

https://www.mt.com/au/en/home/products/Industrial_Weighing_Solutions/Terminals-and-Controllers/terminals-bench-floor-scales/advanced-bench-floor-applications/IND780/IND780_.html#overviewpm
https://sidsecure.au/blog/cve-2021-40661/?_sm_pdc=1&_sm_rid=MRRqb4KBDnjBMJk24b40LMS3SKqPMqb4KVn32Kr
https://nvd.nist.gov/vuln/detail/CVE-2021-40661
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40661
https://github.com/Live-Hack-CVE/CVE-2021-40661