PT-2023-3040 · Tenda · Tenda G103

CVE-2023-27076

·

Publicado

2023-02-27

·

Atualizado

2023-05-26

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda G103 version 1.0.0.5
Description A command injection issue allows an attacker to execute arbitrary code via the language parameter. This can compromise the integrity, availability, and confidentiality of protected information. The vulnerability is related to the failure to neutralize special elements used in the operating system command.
Recommendations For Tenda G103 version 1.0.0.5, consider disabling the language parameter until a patch is available to prevent exploitation. Restrict access to the affected module to minimize the risk of arbitrary code execution. Avoid using the language parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03105
CVE-2023-27076

Produtos afetados

Tenda G103