Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hpf7-2hg3-3g3h

Опубликовано: 14 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

EPSS

Процентиль: 86%
0.0274
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.1
nvd
около 1 года назад

A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

EPSS

Процентиль: 86%
0.0274
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-74