Описание
The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute arbitrary commands via shell metacharacters in the ping_ipaddr parameter.
Комментарий
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Ссылки
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:h:seowonintech:swc-9100:-:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.01874
Низкий
8.3 High
CVSS2
Дефекты
CWE-20
Связанные уязвимости
github
больше 3 лет назад
The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute arbitrary commands via shell metacharacters in the ping_ipaddr parameter.
EPSS
Процентиль: 83%
0.01874
Низкий
8.3 High
CVSS2
Дефекты
CWE-20