Описание
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP request sent by a remote, authenticated attacker to /GponForm/device_Form?script/.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:nokia:i-240w-q_gpon_ont_firmware:3fe54567bozj19:*:*:*:*:*:*:*
cpe:2.3:h:nokia:i-240w-q_gpon_ont:-:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.10177
Средний
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-78
CWE-77
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP request sent by a remote, authenticated attacker to /GponForm/device_Form?script/.
EPSS
Процентиль: 93%
0.10177
Средний
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-78
CWE-77