Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2642-rv5v-5j93

Опубликовано: 11 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden parameter which doesn't appear in POST body, but exist in cgi binary. This leads to command injection in page /ledonoff.shtml.

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden parameter which doesn't appear in POST body, but exist in cgi binary. This leads to command injection in page /ledonoff.shtml.

EPSS

Процентиль: 89%
0.05029
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden parameter which doesn't appear in POST body, but exist in cgi binary. This leads to command injection in page /ledonoff.shtml.

EPSS

Процентиль: 89%
0.05029
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77