Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-19239

Опубликовано: 20 дек. 2018
Источник: nvd
CVSS3: 7.2
CVSS2: 9
EPSS Низкий

Описание

TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remote attackers to execute arbitrary commands via three parameters (dhcpd_start, dhcpd_end, and lan_ipaddr) passed to the apply.cgi binary through a POST request.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:trendnet:tew-673gru_firmware:1.00b40:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tew-673gru:-:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03398
Низкий

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.2
github
больше 3 лет назад

TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remote attackers to execute arbitrary commands via three parameters (dhcpd_start, dhcpd_end, and lan_ipaddr) passed to the apply.cgi binary through a POST request.

EPSS

Процентиль: 87%
0.03398
Низкий

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78