Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-30105

Опубликовано: 18 мая 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vulnerable parameters], are not properly sanitized after being submitted to the web interface in a POST request. With specially crafted parameters, it is possible to inject a an OS command which will be executed with root privileges, as the web interface, and all processes on the device, run as root.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:belkin:n300_firmware:1.00.08:*:*:*:*:*:*:*
cpe:2.3:h:belkin:n300:-:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03438
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vulnerable parameters], are not properly sanitized after being submitted to the web interface in a POST request. With specially crafted parameters, it is possible to inject a an OS command which will be executed with root privileges, as the web interface, and all processes on the device, run as root.

EPSS

Процентиль: 87%
0.03438
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-78