← Advisories

TEM Opera Plus FM Family Transmitter 35.45 Remote Code Execution

Critical
Advisory ID
ZSL-2023-5799
Release Date
25 October 2023
Vendor
Telecomunicazioni Elettro Milano (TEM) S.r.l. - https://www.tem-italy.it
Affected Version
Software version: 35.45, Webserver version: 1.7
Tested On
Webserver
Summary

This new line of Opera plus FM Transmitters combines very high efficiency, high reliability and low energy consumption in compact solutions. They have innovative functions and features that can eliminate the costs required by additional equipment: automatic exchange of audio sources, built-in stereo encoder, integrated RDS encoder, parallel I/O card, connectivity through GSM telemetry and/or TCP IP / SNMP / SMTP Webserver.

Description

The device allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication. The MPFS2 file system module provides a light-weight read-only file system that can be stored in external EEPROM, external serial Flash, or internal Flash program memory. This file system serves as the basis for the HTTP2 web server module, but is also used by the SNMP module and is available to other applications that require basic read-only storage capabilities. This can be exploited to overwrite the flash program memory that holds the web server's main interfaces and execute arbitrary code.

Proof of Concept
Disclosure Timeline
18.08.2023Vulnerabilikty discovered.
22.08.2023Vendor contacted.
05.10.2023No response from the vendor.
06.10.2023Vendor contacted.
08.10.2023No response from the vendor.
09.10.2023CERT Serbia contacted.
09.10.2023CERT Serbia responded asking more details. Created incident ID: 355655.
09.10.2023Replied to CERT Serbia.
24.10.2023Asked CERT Serbia for status update.
25.10.2023No response from CERT Serbia.
25.10.2023Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
25.10.2023Initial release
03.11.2023Added reference [3] and [4]
28.02.2024Added reference [5]
06.03.2024Added reference [6]
03.10.2024Added reference [7], [8] and [9]