Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Josue Rojas

#31049de 53,638
8.3CVSS total
Vulnerabilidades · 1
PT-2014-3280
8.3
2014-02-04
Seowon Intech · Swc-9100 · CVE-2013-7179
**Name of the Vulnerable Software and Affected Versions** Seowon Intech SWC-9100 routers (affected versions not specified) **Description** The issue concerns the ping functionality in the cgi-bin/diagnostic.cgi file, which allows remote attackers to execute arbitrary commands. This is achieved by injecting shell metacharacters into the `ping ipaddr` parameter. **Recommendations** For Seowon Intech SWC-9100 routers, consider restricting access to the cgi-bin/diagnostic.cgi file as a temporary workaround until a patch is available. Avoid using the `ping ipaddr` parameter in the vulnerable API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.