A remote command injection vulnerability exists in IPFire 2.19 within the ids.cgi script. The OINKCODE parameter is improperly sanitized and is passed directly to a shell, allowing attackers to inject arbitrary commands. This vulnerability can be exploited by authenticated users or via CSRF attacks.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit PoC for CVE-2017-9757, an authenticated OS command injection flaw in IPFire 2.19's /cgi-bin/ids.cgi via the OINKCODE parameter. The repository contains three files: a license, a detailed README, and one executable Python script (ipfire_oinkcode_rce.py). The script is the sole code artifact and serves as the main entry point. Exploit flow: it builds a target base URL, authenticates with HTTP Basic Auth using requests.Session, optionally fingerprints the target by requesting /cgi-bin/pakfire.cgi and parsing the returned version string with a regex, then—if the target appears within the supported vulnerable range or the check is skipped—POSTs form data to /cgi-bin/ids.cgi with OINKCODE set to a backtick-wrapped Perl one-liner. That Perl payload opens a reverse TCP shell to the operator-supplied listener address and port. Main capabilities: authenticated version fingerprinting, vulnerable-range validation modeled after the Metasploit module, exploit delivery to the vulnerable CGI, and reverse-shell callback generation. The script intentionally does not rely on reflected command output in the HTTP body; instead it treats HTTP 200 or a read timeout after payload dispatch as practical indicators that the request was accepted. This makes it more operational than a simple detection script, but it is still a PoC rather than a full framework because the payload is fixed to a Perl reverse shell and customization is limited to listener host/port and Perl path. Notable observables include the target CGI paths /cgi-bin/pakfire.cgi and /cgi-bin/ids.cgi, default HTTPS service on port 444, HTTP Basic Auth usage, a custom User-Agent string of IPFIRE-Authorized-Lab-PoC, and a reverse TCP callback to the attacker-controlled <lhost>:<lport>. The exploit targets IPFire systems with valid credentials and requires Perl plus outbound connectivity from the firewall appliance to the listener.
This repository contains a single Metasploit module (modules/exploits/linux/http/ipfire_oinkcode_exec.rb) targeting a remote command execution vulnerability (CVE-2017-9757) in IPFire, an open-source Linux firewall distribution. The exploit abuses the OINKCODE field in the /cgi-bin/ids.cgi endpoint, allowing an authenticated attacker to execute arbitrary shell commands on IPFire systems running versions prior to 2.19 Core Update 110. The module requires valid credentials (default user: admin) and sends a crafted POST request to the vulnerable endpoint, injecting the payload as a shell command. The module also includes a check method to verify the target's version and authentication status via the /cgi-bin/pakfire.cgi endpoint. The exploit is operational, allowing customizable command execution, and is implemented in Ruby as part of the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.