Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9hpw-wrhw-6g76

Опубликовано: 23 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel.

The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel.

EPSS

Процентиль: 14%
0.00047
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-20

Связанные уязвимости

nvd
9 месяцев назад

The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploited by an attacker to extend his knowledge of the system and compromise other devices. The information is filtered by the logs function of the web panel.

EPSS

Процентиль: 14%
0.00047
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-20