CVE-2019-25483
8.4Comtrend · AR-5310
The Comtrend AR-5310 router contains a restricted shell escape vulnerability that allows local users to execute arbitrary commands by leveraging the command substitution operator.
Executive summary
A restricted shell escape vulnerability in the Comtrend AR-5310 router allows local users to achieve full command execution, posing a significant risk of total device compromise.
Vulnerability
The device implements a restricted shell that fails to filter the command substitution operator $( ). By passing this operator as an argument to permitted commands, such as ping, a local user can bypass command restrictions and gain unrestricted shell access.
Business impact
The ability to escape the restricted shell allows an attacker to gain full control over the router operating system. This level of access could facilitate lateral movement within the network, interception of traffic, or the permanent bricking of the hardware. With a CVSS score of 8.4, this vulnerability is considered high severity, reflecting the potential for total system compromise.
Remediation
Immediate Action: Since no official patch is currently identified, administrators should restrict physical and logical access to the device management interface to trusted personnel only.
Proactive Monitoring: Review system logs for unusual command execution patterns or attempts to use shell operators in command arguments.
Compensating Controls: Disable telnet access where possible and enforce strict network segmentation to limit the impact if the device is compromised.
Exploitation status
Public Exploit Available: Yes, a public proof of concept is available via ExploitDB (EDB-ID 47149).
Analyst recommendation
Given the high CVSS score and the public availability of exploit code, this vulnerability poses a credible threat to the integrity of the affected Comtrend devices. Organizations currently using this hardware should prioritize isolating these units from sensitive network segments and transition to supported, patched hardware alternatives as soon as possible to mitigate the risk of unauthorized system access.
Sources
Originally found and disclosed by AMRI Amine, per the CVE Program record.
- ExploitDB-47149 Exploit / PoC
- VulnCheck Advisory: Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k Restricted Shell Escape Third-party advisory