Tuesday, August 9, 2016

hndUnblock.cgi wget calls

GET /hndUnblock.cgi HTTP/1.0
User-Agent: Wget(linux)

Saw this http request in the logs, what could it mean? It appears that in April 2014 there was a Linksys router vulnerability. The web admin page on routers provides the hndUnblock.cgi page to administrate. This page could be accessed by and attacker it apparently contains an OS command injection vulnerability that allows execution of commands against the router. So this attacker is simply running an automated linux script that calls the wget command and is looking to see if the vulnerable hndUnblock.cgi page exists.

