Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m9j-f7hm-696q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.

There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.

EPSS

Процентиль: 85%
0.02395
Низкий

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 7.2
nvd
около 5 лет назад

There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.

EPSS

Процентиль: 85%
0.02395
Низкий

Дефекты

CWE-77