Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qr4g-xxx6-244x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest.

Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest.

EPSS

Процентиль: 100%
0.92677
Критический

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest.

EPSS

Процентиль: 100%
0.92677
Критический

Дефекты

CWE-78