Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g7vj-8g3h-7p8r

Опубликовано: 22 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when downloading new firmware.

Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when downloading new firmware.

EPSS

Процентиль: 89%
0.04336
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when downloading new firmware.

EPSS

Процентиль: 89%
0.04336
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77