Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c86c-pc2p-fq87

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled and the attacker can authenticate as admin from the local network.

Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled and the attacker can authenticate as admin from the local network.

EPSS

Процентиль: 71%
0.00668
Низкий

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 6.7
nvd
почти 6 лет назад

Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled and the attacker can authenticate as admin from the local network.

EPSS

Процентиль: 71%
0.00668
Низкий

Дефекты

CWE-74