Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-16752

Опубликовано: 20 сент. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Средний

Описание

LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of admin for the admin account may be used in some cases.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:linknet-usa:lw-n605r_firmware:12.20.2.1486:*:*:*:*:*:*:*
cpe:2.3:h:linknet-usa:lw-n605r:-:*:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.49862
Средний

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of admin for the admin account may be used in some cases.

EPSS

Процентиль: 98%
0.49862
Средний

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78