T03 · Remote Payload Retrieval and Execution
- Location
references/eworm-scripts.md:29- Finding
Mutable Third-Party RouterOS Code Is Downloaded, Executed, and Automatically Updated
- Content
View full analysis
"data"); } /system/script { run global-config; run global-functions; } # Loads configuration and functions at boot /system/scheduler/add name="global-scripts" start-time=startup \ on-event="/system/script { run global-config; run global-functions; }" # Optional daily automatic script update /system/scheduler/add name="ScriptInstallUpdate" start-time=startup interval=1d \ on-event=":global ScriptInstallUpdate; \$ScriptInstallUpdate;" ``` ### Technical Analysis The instructions retrieve mutable RouterOS source from an external domain, save it as privileged device scripts, and immediately execute it. The downloaded payload is not pinned to an immutable release or commit and is not authenticated with a code signature or expected cryptographic digest. TLS validates only the server connection at retrieval time. It does not protect against compromise of the upstream project, hosting environment, domain, or authorized publishing account. The daily update scheduler allows the effective payload to change after the Skill and initial script version have been reviewed. The startup scheduler also causes downloaded code to execute after router reboots. These behaviors exceed the minimum permissions needed for ordinary router monitoring or notification tasks. ### Attack Path 1. An attacker compromises the upstream publishing account, hosting service, DNS path, or another component capable of changing the `.rsc` responses. 2. The attacker replaces one of the mutable ...[truncated 825 chars]- Remediation
View remediation
