PT-2018-11744 · Buffalo · Buffalo Ts5600D1206

Publicado

2018-11-26

·

Atualizado

2019-10-03

·

CVE-2018-13320

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Buffalo TS5600D1206 version 3.70-0.10
Description The issue allows attackers to execute system commands via the adminUsername and adminPassword parameters in the network.set auth settings function.
Recommendations For Buffalo TS5600D1206 version 3.70-0.10, consider restricting access to the network.set auth settings function until a patch is available, and avoid using the adminUsername and adminPassword parameters in this function to minimize the risk of exploitation.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-13320

Produtos afetados

Buffalo Ts5600D1206