Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xjj9-3q77-6c55

Опубликовано: 03 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint.

A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint.

EPSS

Процентиль: 98%
0.23666
Средний

7.2 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.2
nvd
около 4 лет назад

A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint.

CVSS3: 7.2
fstec
около 4 лет назад

Уязвимость компонента statussupport_diagnostic_tracing.json микропрограммного обеспечения маршрутизаторов SerComm h500s, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 98%
0.23666
Средний

7.2 High

CVSS3

Дефекты

CWE-78