Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r3cr-jc72-pwfx

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.

Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.

EPSS

Процентиль: 53%
0.00303
Низкий

8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8
nvd
больше 2 лет назад

Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function that calls a user-provided package name by instead providing a package with a malicious name that contains an OS command injection payload.

EPSS

Процентиль: 53%
0.00303
Низкий

8 High

CVSS3

Дефекты

CWE-78