CVE-2018-25134

Synaccess · netBooter

Synaccess netBooter devices contain an authentication bypass vulnerability allowing unauthenticated attackers to create new administrative accounts via the webNewAcct.cgi script.

Executive summary

The Synaccess netBooter power management series is vulnerable to an authentication bypass, allowing attackers to gain full administrative control without credentials.

Vulnerability

This vulnerability (CWE-306) occurs due to missing authentication checks in the webNewAcct.cgi script, which allows any remote, unauthenticated attacker to inject a POST request and create a new administrative user account.

Business impact

A successful exploit grants the attacker full administrative access to power management controls. This could lead to physical site disruptions, unauthorized power cycles of critical infrastructure, or complete takeover of the device, justifying the 9.8 CVSS severity rating.

Remediation

Immediate Action: Ensure all netBooter devices are isolated behind a VPN or restricted network, preventing direct internet access to the web management interface.

Proactive Monitoring: Review device account logs for the creation of unexpected user accounts and monitor network traffic for POST requests to the 'webNewAcct.cgi' script.

Compensating Controls: Use network-level access control lists (ACLs) to limit access to the web interface to authorized management IP addresses only.

Exploitation status

Public Exploit Available: Yes — a public exploit is available via ExploitDB (45920).

Analyst recommendation

The ability to create arbitrary admin accounts makes this a critical security priority for any facility relying on netBooter devices. Immediate network isolation is required to prevent unauthorized remote access while awaiting official vendor firmware updates.