CVE-2017-20222
7.5Telesquare · SKT LTE Router SDT-CS3B1
Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 allows unauthenticated remote attackers to trigger a device reboot via the lte.cgi endpoint.
Executive summary
The Telesquare SKT LTE Router SDT-CS3B1 contains an unauthenticated remote reboot vulnerability that enables attackers to cause a persistent denial of service.
Vulnerability
The device fails to perform authentication checks on the lte.cgi endpoint. An unauthenticated attacker can send a POST request with the Command=Reboot parameter to force an immediate system restart.
Business impact
Successful exploitation results in a denial of service, as the router becomes unavailable during the reboot cycle. This impacts business continuity by disrupting network connectivity for all devices reliant on the router for internet or local network access. Given the CVSS score of 7.5, this is considered a high-severity risk for environments where uptime is critical.
Remediation
Immediate Action: As no official patch is currently identified, administrators should restrict network access to the management interface of the affected routers to trusted IP addresses only.
Proactive Monitoring: Review device access logs for suspicious POST requests directed at the /cgi-bin/lte.cgi endpoint, particularly those originating from untrusted or external networks.
Compensating Controls: Deploy a Web Application Firewall or network access control list to block unauthorized access to the management web interface and specifically filter requests containing the Command=Reboot parameter.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exploit is available via ExploitDB (EDB-ID 43401) and Packet Storm Security.
Analyst recommendation
Due to the availability of public exploit code and the lack of a vendor-supplied patch, this device should be removed from public-facing network segments immediately. Implement strict network segmentation and firewall rules to ensure only authorized administrative workstations can communicate with the device management interface until the vendor provides a secure firmware update.
More Telesquare CVEs
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- Zero Science Lab Disclosure Third-party advisory
- CXSecurity Third-party advisory
- Packet Storm Security Exploit / PoC
- Exploit DB Exploit / PoC
- IBM X-Force Exchange Vulnerability database entry
- VulnCheck Advisory: Telesquare SKT LTE Router SDT-CS3B1 Unauthenticated Remote Reboot Third-party advisory