SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP TP-LINK Cloud Cameras NCXXX Bonjour command injection attempt
This rule is looking precisely for a command injection within the 'sysname' parameter of the setsysname.fcgi page.
This rule is triggered by an attempt to exploit CVE-2020-12109 via a command injection through HTTP.
Public information/Proof of Concept available
No known false positives
Cisco Talos Intelligence Group
No rule groups
CVE-2020-12109 |
Loading description
|
Tactic: Initial Access
Technique: Exploit Public-Facing Application
For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org