PT-2018-5427 · Planex · Planex Cs-W50Hd
Kenney Lu
·
Published
2018-08-24
·
Updated
2019-10-03
·
CVE-2017-12573
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
PLANEX CS-W50HD devices with firmware before 030720
Description:
A command-injection issue exists in the web management UI on the NAS settings page "/cgi-bin/nasset.cgi". An attacker can send a crafted HTTP POST request to execute arbitrary code, but authentication is required before executing the attack.
Recommendations:
For PLANEX CS-W50HD devices with firmware before 030720, update the firmware to version 030720 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/cgi-bin/nasset.cgi" endpoint to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Planex Cs-W50Hd