Описание
There is a command injection vulnerability in the HG8045Q product. When the command-line interface is enabled, which is disabled by default, attackers with administrator privilege could execute part of commands.
Ссылки
- Third Party Advisory
- Permissions RequiredVendor Advisory
- Third Party Advisory
- Permissions RequiredVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
Одно из
cpe:2.3:o:huawei:hg8045q_firmware:v300r016c00spc110:*:*:*:*:*:*:*
cpe:2.3:o:huawei:hg8045q_firmware:v300r018c10:*:*:*:*:*:*:*
cpe:2.3:h:huawei:hg8045q:-:*:*:*:*:*:*:*
EPSS
Процентиль: 30%
0.00108
Низкий
6.7 Medium
CVSS3
6.9 Medium
CVSS2
Дефекты
CWE-78
Связанные уязвимости
github
больше 3 лет назад
There is a command injection vulnerability in the HG8045Q product. When the command-line interface is enabled, which is disabled by default, attackers with administrator privilege could execute part of commands.
EPSS
Процентиль: 30%
0.00108
Низкий
6.7 Medium
CVSS3
6.9 Medium
CVSS2
Дефекты
CWE-78