Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-13976

Опубликовано: 09 июн. 2020
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping command. Exploitation through CSRF might be possible. NOTE: software maintainers consider the report invalid because it refers to an old software version, requires administrative privileges, and does not provide access beyond that already available to administrative users

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:dd-wrt:dd-wrt:*:*:*:*:*:*:*:*
Версия до 16214 (включая)

EPSS

Процентиль: 73%
0.00763
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

** DISPUTED ** An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping command. Exploitation through CSRF might be possible. NOTE: software maintainers consider the report invalid because it refers to an old software version, requires administrative privileges, and does not provide access beyond that already available to administrative users.

EPSS

Процентиль: 73%
0.00763
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-78