T03 · Remote Payload Retrieval and Execution
- Location
scripts/install_devkit_webui.sh:122- Finding
Unauthenticated PKCS#7 signer permits untrusted root-level payload execution
- Content
View full analysis
Vulnerability Details
File Location:
scripts/install_devkit_webui.sh, lines 122-163 and 167-185
Vulnerability Type: Improper signature trust validation followed by remote code execution
Risk Level: HighVulnerable Code
bash wget -c "${DEVKIT_URL}" -O "${DEVKIT_PKG}" 2>&1 | tail -5 echo "Download complete ✓" echo "" echo "=== [3.5/6] Verify Digital Signature (.p7s) ===" DEVKIT_SIG="${DEVKIT_PKG}.p7s" wget -c "${DEVKIT_SIG_URL}" -O "${DEVKIT_SIG}" 2>&1 | tail -5 echo "Signature downloaded ✓" # Verify PKCS#7 detached signature using OpenSSL # -inform DER: .p7s files are DER-encoded # -content: the file being signed # -noverify: skip certificate chain validation (Huawei self-signed cert), still verifies signature-content binding VERIFY_OK=false if command -v openssl >/dev/null 2>&1; then if openssl cms -verify -inform DER -binary -in "${DEVKIT_SIG}" -content "${DEVKIT_PKG}" -noverify -out /dev/null >/dev/null 2>&1; then VERIFY_OK=true elif openssl smime -verify -inform DER -binary -in "${DEVKIT_SIG}" -content "${DEVKIT_PKG}" -noverify -out /dev/null >/dev/null 2>&1; then VERIFY_OK=true fi fi if [[ "${VERIFY_OK}" == "true" ]]; then echo "Digital signature verification PASSED ✓" else echo "⚠️ Digital signature verification FAILED!" exit 1 fi mkdir -p DevKit-All tar -xzf "${DEVKIT_PKG}" -C DevKit-All cd DevKit-All/${DEVKIT_DIR} ... spawn bash install.sh -aTechnical Analysis
The script downloads both the DevKit archive and its detached
.p7ssignature from the same externally supplied location. It then invokes OpenSSL with-noverify, which verifies that the signature mathematically matches the archive but does not establish that the signing certificate belongs to Huawei or chains to an approved trust anchor.Consequently, a source capable of supplying both files can generate its own certificate, sign an arbitrary archive, and satisfy this check. The archive is extracted and its `insta ...[truncated 1348 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin an approved Huawei signing certificate, public key, or certificate fingerprint in the Skill.
- Remove
-noverifyand validate the signer against a controlled trust store and expected signer identity. - If a private or self-signed vendor certificate is required, distribute that certificate through the audited Skill package or another authenticated channel and pass it explicitly as the trust anchor.
- Do not obtain both the payload and its sole trust material from the same configurable URL.
- Restrict custom package URLs unless the user also supplies separately authenticated trust material.
- Validate archive members before extraction to reject absolute paths,
..traversal, links escaping the extraction directory, and unexpected executable entry points. - Abort before extraction or execution whenever publisher authentication cannot be completed.
