Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2w4w-qvp3-4g7g

Опубликовано: 21 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.2

Описание

A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted "salia.ini" files. The .ini file can contain several "commands" that could be exploited by an attacker to export or modify the device configuration, enable an SSH backdoor  or perform other administrative actions. Ultimately, this backdoor also allows arbitrary execution of OS commands.

A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted "salia.ini" files. The .ini file can contain several "commands" that could be exploited by an attacker to export or modify the device configuration, enable an SSH backdoor  or perform other administrative actions. Ultimately, this backdoor also allows arbitrary execution of OS commands.

EPSS

Процентиль: 9%
0.00032
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-749

Связанные уязвимости

CVSS3: 6.2
nvd
9 месяцев назад

A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted "salia.ini" files. The .ini file can contain several "commands" that could be exploited by an attacker to export or modify the device configuration, enable an SSH backdoor  or perform other administrative actions. Ultimately, this backdoor also allows arbitrary execution of OS commands.

EPSS

Процентиль: 9%
0.00032
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-749