← Advisories

devolo dLAN 550 duo+ Starter Kit Remote Code Execution

High
Advisory ID
ZSL-2019-5508
Release Date
03 February 2019
Vendor
Affected Version
dLAN 500 AV Wireless+ 3.1.0-1 (i386)
Tested On
Linux 2.6.31
Summary

Devolo dLAN® 550 duo+ Starter Kit is Powerlineadapter which is a cost-effective and helpful networking alternative for any location without structured network wiring. Especially in buildings or residences lacking network cables or where updating the wiring would be expensive and complicated, Powerline adapters provide networking at high transmission rates.

Description

The devolo firmware has what seems to be a 'hidden' services which can be enabled by authenticated attacker via the the htmlmgr CGI script. This allows the attacker to start services that are deprecated or discontinued and achieve remote arbitrary code execution with root privileges.

Proof of Concept
Disclosure Timeline
04.10.2017Vulnerability discovered.
11.10.2017Vendor contacted via email.
14.10.2017No response from the vendor.
15.10.2017Second attempt - Vendor contacted via email.
02.02.2019No response from the vendor.
03.02.2019Public security advisory released.
Credits
Vulnerability discovered by Stefan Petrushevski
References
Changelog
03.02.2019Initial release
10.02.2019Added reference [2], [3], [4] and [5]
23.03.2026Added reference [6]