PT-2018-13042 · Mystrom · Mystrom Wifi Switch Eu

Almeroth

+1

·

Published

2018-08-30

·

Updated

2018-11-09

·

CVE-2018-15477

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions myStrom WiFi Switch V1 versions prior to 2.66
Description The issue concerns a lack of sanitization for a parameter received from the cloud, which is then used in an OS command. This allows malicious servers to execute operating system commands on the device.
Recommendations For versions prior to 2.66, update to version 2.66 or later to resolve the issue.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15477

Affected Products

Mystrom Wifi Switch Eu