PT-2019-15771 · Phicomm · Phicomm K2
Published
2019-11-18
·
Updated
2020-08-24
·
CVE-2019-19117
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PHICOMM K2(PSG1218) version V22.5.9.163
Description
The issue allows remote authenticated users to execute any command via shell metacharacters in the
autoUpTime parameter of the /usr/lib/lua/luci/controller/admin/autoupgrade.lua file. This can be exploited through the cgi-bin/luci endpoint.Recommendations
For PHICOMM K2(PSG1218) version V22.5.9.163, avoid using the
autoUpTime parameter in the affected API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the autoupgrade.lua file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phicomm K2