Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q738-7qq7-r8ff

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows man-in-the-middle attackers to execute arbitrary commands with root level privileges.

Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows man-in-the-middle attackers to execute arbitrary commands with root level privileges.

EPSS

Процентиль: 87%
0.0313
Низкий

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.1
nvd
около 5 лет назад

Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows man-in-the-middle attackers to execute arbitrary commands with root level privileges.

EPSS

Процентиль: 87%
0.0313
Низкий

Дефекты

CWE-77