PT-2019-9650 · Cerio · Cerio Dt-300N
Publicado
2019-06-18
·
Atualizado
2019-06-18
·
CVE-2018-18852
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cerio DT-300N versions 1.1.6 through 1.1.12
Description
The issue arises from improper input validation in the web-interface PING feature, which uses Save.cgi to execute a ping command, allowing OS command injection. This has been exploited in the wild.
Recommendations
For Cerio DT-300N versions 1.1.6 through 1.1.12, consider disabling the Save.cgi functionality related to the PING feature as a temporary workaround until a patch is available. Restrict access to the web-interface PING feature to minimize the risk of exploitation.
Exploit
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cerio Dt-300N