Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fv43-xxv4-v4x9

Опубликовано: 01 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection.

D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection.

EPSS

Процентиль: 94%
0.11888
Средний

8.8 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection.

EPSS

Процентиль: 94%
0.11888
Средний

8.8 High

CVSS3

Дефекты

CWE-77