T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/roku_control.py:62- Finding
Unvalidated Network Destinations Enable Restricted SSRF and Unauthorized Device Control
- Content
View full analysis
Dict[str, str]: """Get device info from a specific IP""" url = f"http://{ip}:{ROKU_PORT}/query/device-info" response = requests.get(url, timeout=2) ``` The manually supplied `--ip` value is also accepted without validation: ```python parser.add_argument("--ip", help="Roku device IP address") ``` ```python controller = RokuController(args.ip) ``` The unvalidated value is then used by information-query and state-changing operations: ```python url = f"http://{self.roku_ip}:{ROKU_PORT}/query/device-info" response = requests.get(url, timeout=5) ``` ```python url = f"http://{self.roku_ip}:{ROKU_PORT}/query/apps" response = requests.get(url, timeout=5) ``` ```python url = f"http://{self.roku_ip}:{ROKU_PORT}/keypress/{key}" response = requests.post(url, timeout=5) ``` ```python url = f"http://{self.roku_ip}:{ROKU_PORT}/launch/{app_id}" response = requests.post(url, timeout=5) ``` ```python for char in text: url = f"http://{self.roku_ip}:{ROKU_PORT}/keypress/Lit_ ...[truncated 3464 chars]- Remediation
View remediation
