Логотип exploitDog
bind:CVE-2022-43654
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-43654

Количество 3

Количество 3

nvd логотип

CVE-2022-43654

почти 2 года назад

NETGEAR CAX30S SSO Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR CAX30S routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the token parameter provided to the sso.php endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18227.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-8h2v-755h-m3p5

почти 2 года назад

NETGEAR CAX30S SSO Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR CAX30S routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the token parameter provided to the sso.php endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18227.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2023-01185

больше 3 лет назад

Уязвимость сценария sso.php микропрограммного обеспечения маршрутизаторов NETGEAR CAX30, CAX30S, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-43654

NETGEAR CAX30S SSO Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR CAX30S routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the token parameter provided to the sso.php endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18227.

CVSS3: 8.8
3%
Низкий
почти 2 года назад
github логотип
GHSA-8h2v-755h-m3p5

NETGEAR CAX30S SSO Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR CAX30S routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the token parameter provided to the sso.php endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18227.

CVSS3: 8.8
3%
Низкий
почти 2 года назад
fstec логотип
BDU:2023-01185

Уязвимость сценария sso.php микропрограммного обеспечения маршрутизаторов NETGEAR CAX30, CAX30S, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу