PT-2016-5117 · Syslink+1 · Syslink Sl-1000+1
Jeremy Allen
+1
·
Published
2016-04-25
·
Updated
2016-05-04
·
CVE-2016-2332
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware prior to 01A.8
Description
The issue allows remote authenticated users to execute arbitrary commands. This is achieved via the
dnsmasq parameter, also known as 5066, in the flu.cgi script within the web interface.Recommendations
For firmware versions prior to 01A.8, update the firmware to version 01A.8 or later to resolve the issue.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Syslink Sl-1000
Dnsmasq