Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9mrw-6xpv-33mx

Опубликовано: 10 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

Command injection vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability could allow an authenticated user to execute commands inside the router by making a POST request to the URL “/boaform/admin/formUserTracert”.

Command injection vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability could allow an authenticated user to execute commands inside the router by making a POST request to the URL “/boaform/admin/formUserTracert”.

EPSS

Процентиль: 52%
0.00287
Низкий

8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8
nvd
больше 1 года назад

Command injection vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability could allow an authenticated user to execute commands inside the router by making a POST request to the URL “/boaform/admin/formUserTracert”.

EPSS

Процентиль: 52%
0.00287
Низкий

8 High

CVSS3

Дефекты

CWE-78