← Advisories

TEM Opera Plus FM Family Transmitter 35.45 XSRF

High
Advisory ID
ZSL-2023-5800
Release Date
25 October 2023
Vendor
Telecomunicazioni Elettro Milano (TEM) S.r.l. - https://www.tem-italy.it
Affected Version
Software version: 35.45, Webserver version: 1.7
Tested On
Webserver
Summary

This new line of Opera plus FM Transmitters combines very high efficiency, high reliability and low energy consumption in compact solutions. They have innovative functions and features that can eliminate the costs required by additional equipment: automatic exchange of audio sources, built-in stereo encoder, integrated RDS encoder, parallel I/O card, connectivity through GSM telemetry and/or TCP IP / SNMP / SMTP Webserver.

Description

The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

Proof of Concept
Disclosure Timeline
18.08.2023Vulnerabilikty discovered.
22.08.2023Vendor contacted.
05.10.2023No response from the vendor.
06.10.2023Vendor contacted.
08.10.2023No response from the vendor.
09.10.2023CERT Serbia contacted.
09.10.2023CERT Serbia responded asking more details. Created incident ID: 355655.
09.10.2023Replied to CERT Serbia.
24.10.2023Asked CERT Serbia for status update.
25.10.2023No response from CERT Serbia.
25.10.2023Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
25.10.2023Initial release
03.11.2023Added reference [1] and [2]
28.02.2024Added reference [3]
06.03.2024Added reference [4]
03.10.2024Added reference [5], [6] and [7]