Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xv64-jjpm-mgjv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.

EPSS

Процентиль: 61%
0.00406
Низкий

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 6.4
nvd
почти 6 лет назад

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.

EPSS

Процентиль: 61%
0.00406
Низкий

Дефекты

CWE-74