Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q25g-m88j-xmgx

Опубликовано: 02 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.

EPSS

Процентиль: 70%
0.00654
Низкий

8.8 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.8
nvd
9 месяцев назад

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.

CVSS3: 8.8
fstec
9 месяцев назад

Уязвимость функции setLanCfg() микропрограммного обеспечения маршрутизаторов Tenda RX2 Pro, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 70%
0.00654
Низкий

8.8 High

CVSS3

Дефекты

CWE-77