Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rgm2-gvmf-vqr7

Опубликовано: 17 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials and execute unblocked default busybox functionality to trigger this vulnerability.

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials and execute unblocked default busybox functionality to trigger this vulnerability.

EPSS

Процентиль: 77%
0.01013
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-77
CWE-798

Связанные уязвимости

CVSS3: 6.8
nvd
почти 2 года назад

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials and execute unblocked default busybox functionality to trigger this vulnerability.

EPSS

Процентиль: 77%
0.01013
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-77
CWE-798