Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cm3-3v62-g64q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

** DISPUTED ** An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping command. Exploitation through CSRF might be possible. NOTE: software maintainers consider the report invalid because it refers to an old software version, requires administrative privileges, and does not provide access beyond that already available to administrative users.

** DISPUTED ** An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping command. Exploitation through CSRF might be possible. NOTE: software maintainers consider the report invalid because it refers to an old software version, requires administrative privileges, and does not provide access beyond that already available to administrative users.

EPSS

Процентиль: 73%
0.00763
Низкий

8.8 High

CVSS3

Дефекты

CWE-352
CWE-78

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping command. Exploitation through CSRF might be possible. NOTE: software maintainers consider the report invalid because it refers to an old software version, requires administrative privileges, and does not provide access beyond that already available to administrative users

EPSS

Процентиль: 73%
0.00763
Низкий

8.8 High

CVSS3

Дефекты

CWE-352
CWE-78