Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-23584

Опубликовано: 23 нояб. 2022
Источник: nvd
CVSS3: 9.8
EPSS Средний

Описание

Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:optilinknetwork:op-xt71000n_firmware:3.3.1-191028:*:*:*:*:*:*:*
cpe:2.3:h:optilinknetwork:op-xt71000n:2.2:*:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.1899
Средний

9.8 Critical

CVSS3

Дефекты

CWE-77
CWE-77

Связанные уязвимости

CVSS3: 9.8
github
около 3 лет назад

Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.

EPSS

Процентиль: 95%
0.1899
Средний

9.8 Critical

CVSS3

Дефекты

CWE-77
CWE-77