Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jjh2-2h2c-9qqq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all versions before MIPS_A_1022IPV6R3T6P7Y20.

A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all versions before MIPS_A_1022IPV6R3T6P7Y20.

EPSS

Процентиль: 69%
0.00617
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all versions before MIPS_A_1022IPV6R3T6P7Y20.

EPSS

Процентиль: 69%
0.00617
Низкий

Дефекты

CWE-89