In IPFire 2.25-core155, the lfs/backup component does not enforce that the /var/ipfire/backup/bin/backup.pl script is owned by the root user. This allows an unprivileged user to potentially take ownership of backup.pl and replace it with a malicious script. Since backup.pl may later be executed by root, this can lead to arbitrary code execution with root privileges. The vulnerability may also affect other files with improper ownership or permissions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone Python proof-of-concept exploit for CVE-2021-33393 affecting IPFire 2.25 Core Update 156. The repository contains only three files: a LICENSE, a short README with usage instructions, and the main exploit script exploit.py. The exploit is not part of a larger framework. The Python script accepts four arguments: target base URL, username, password, and attacker callback host:port. It constructs the authenticated target endpoint by appending /cgi-bin/pakfire.cgi to the supplied host and uses HTTP Basic Authorization. The core primitive is an authenticated command injection delivered in the POST parameter INSPAKS by prefixing a shell command with a semicolon while setting ACTION=install. Exploit flow: first, it copies the legitimate /var/ipfire/backup/bin/backup.pl to /tmp/backup.pl.bak. Next, it overwrites backup.pl with a bash script containing a reverse shell one-liner that connects to the attacker-controlled host and port using /dev/tcp. It then invokes /usr/local/bin/backupctrl export, which causes the modified backup.pl to execute with root privileges. Finally, it restores the original backup.pl from the temporary backup copy to reduce operational traces and preserve system functionality. Capabilities: authenticated remote command execution, file overwrite of a privileged script, privilege escalation via execution context of backupctrl, reverse shell establishment as root, and cleanup/restoration of the modified file. The script disables TLS verification and suppresses warnings, indicating it is intended for direct use against HTTPS management interfaces with potentially self-signed certificates. Overall, this is an operational exploit with a hardcoded bash reverse-shell payload rather than a detection-only script.
This repository contains a single Metasploit module (modules/exploits/linux/http/ipfire_pakfire_exec.rb) that exploits an authenticated command injection vulnerability (CVE-2021-33393) in the /cgi-bin/pakfire.cgi endpoint of IPFire firewall devices running version 2.25 Core Update 156 and prior. The exploit requires valid credentials for the web interface and network access to the HTTPS service (default port 444). The module works by injecting commands via a POST request to the vulnerable CGI endpoint, overwriting the backup.pl script with a Python payload, and then executing it via the backupctrl binary. The payload is customizable and defaults to a Python Meterpreter reverse shell, running as root. The module also restores the original backup.pl after exploitation. The code is written in Ruby and is fully integrated into the Metasploit framework, making it weaponized and easy to use for post-exploitation activities.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.