Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g5r9-4hpg-33p3

Опубликовано: 25 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the ssid_hex HTTP parameter to construct an OS Command at offset 0x19afc0 of the /root/hpgw binary included in firmware 6.9Z.

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the ssid_hex HTTP parameter to construct an OS Command at offset 0x19afc0 of the /root/hpgw binary included in firmware 6.9Z.

EPSS

Процентиль: 78%
0.01109
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.9
nvd
больше 3 лет назад

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the `ssid_hex` HTTP parameter to construct an OS Command at offset `0x19afc0` of the `/root/hpgw` binary included in firmware 6.9Z.

EPSS

Процентиль: 78%
0.01109
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-78