Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jcv4-m7f3-w7rm

Опубликовано: 28 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.

In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.

EPSS

Процентиль: 94%
0.13515
Средний

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.

EPSS

Процентиль: 94%
0.13515
Средний

9.8 Critical

CVSS3