Vulnerability record · CVE-2021-33393 · published 9 June 2021
CVE-2021-33393: IPFire backup script ownership flaw enables root code execution
Ipfire · Ipfire
IPFire 2.25-core155 does not verify that /var/ipfire/backup/bin/backup.pl is owned by root, so the file may be writable by an unprivileged account. An attacker who can modify it can plant a Trojan horse script that root later executes. The advisory notes similar ownership or permission problems may exist on other files.
Description
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivileged account, which could potentially be used to install a Trojan horse backup.pl script that is later executed by root. Similar problems with the ownership/permissions of other files may be present as well.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with low-privilege network reach, public exploit code and very high EPSS make this a serious root-compromise risk despite no KEV listing.
What it is
IPFire 2.25-core155 does not verify that /var/ipfire/backup/bin/backup.pl is owned by root, so the file may be writable by an unprivileged account. An attacker who can modify it can plant a Trojan horse script that root later executes. The advisory notes similar ownership or permission problems may exist on other files.
Impact
An attacker with a low-privileged account gains arbitrary code execution as root on the IPFire system, giving full control of the firewall and any data or traffic it handles.
Attack surface
The flaw is network-reachable per the CVSS vector (AV:N) and requires low privileges (PR:L) with no user interaction (UI:N). The attacker needs an account or access path that can write to the backup script or another mis-owned file.
Exploitation
CISA KEV does not list this CVE, but public exploit code exists in the references and EPSS is very high (0.587, 99th percentile), indicating elevated real-world exploitation likelihood.
What to do
- Apply the vendor patch commit 6769d909306d7bdc43d64598872126fcf1b217f6 or upgrade IPFire to a release containing it.
- Verify and correct ownership and permissions on /var/ipfire/backup/bin/backup.pl and other files under /var/ipfire so only root can write them.
- Restrict and audit accounts with shell or file access on the IPFire host; remove unnecessary unprivileged users.
- Monitor the backup script and related paths for unexpected content or ownership changes.
- Review the full /var/ipfire tree for similar ownership or permission weaknesses noted in the advisory.
Detection
- Alert on ownership or permission changes to /var/ipfire/backup/bin/backup.pl and other /var/ipfire files.
- Monitor for unexpected modifications to backup.pl content or new files in the backup bin directory.
- Watch for root-owned process execution originating from backup.pl or the backup cron path outside scheduled windows.
- Correlate low-privileged account activity with writes into /var/ipfire paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/163158/IPFire-2.25-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/MucahitSaratar/ipfire-2-25-auth-rce | ExploitThird Party Advisory |
| https://github.com/ipfire/ipfire-2.x/commit/6769d909306d7bdc43d64598872126fcf1b217f6 | PatchThird Party Advisory |
| https://github.com/ipfire/ipfire-2.x/commits/master?since=2021-05-17&until=2021-05-17 | Third Party Advisory |
| http://packetstormsecurity.com/files/163158/IPFire-2.25-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/MucahitSaratar/ipfire-2-25-auth-rce | ExploitThird Party Advisory |
| https://github.com/ipfire/ipfire-2.x/commit/6769d909306d7bdc43d64598872126fcf1b217f6 | PatchThird Party Advisory |
| https://github.com/ipfire/ipfire-2.x/commits/master?since=2021-05-17&until=2021-05-17 | Third Party Advisory |
Track CVE-2021-33393 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33393), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.