PT-2015-2963 · Zyxel · Zyxel Pmg5318-B20A

Karn Ganeshen

·

Publicado

2015-08-25

·

Atualizado

2017-09-15

·

CVE-2015-6018

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ZyXEL PMG5318-B20A versions prior to 1.00(AANC.2)C0
Description The issue is related to the diagnostic-ping implementation, which has inadequate access restrictions. This allows a remote attacker to execute arbitrary commands through the PingIPAddr parameter.
Recommendations For versions prior to 1.00(AANC.2)C0, update the firmware to version 1.00(AANC.2)C0 or later to resolve the issue. As a temporary workaround, consider restricting access to the PingIPAddr parameter to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00060
CVE-2015-6018

Produtos afetados

Zyxel Pmg5318-B20A