Описание
SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attackers to execute arbitrary SQL commands by attempting to establish a TELNET session with a crafted username.
Ссылки
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.3.6 (включая)
Одновременно
cpe:2.3:o:grandstream:gxv3611_hd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:grandstream:gxv3611_hd:*:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.03623
Низкий
7.5 High
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
больше 3 лет назад
SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attackers to execute arbitrary SQL commands by attempting to establish a TELNET session with a crafted username.
EPSS
Процентиль: 88%
0.03623
Низкий
7.5 High
CVSS2
Дефекты
CWE-89