PT-2019-8304 · Billion · Billion 5200W-T
Pedro Ribeiro
·
Published
2019-05-02
·
Updated
2025-10-14
·
CVE-2017-18369
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Billion 5200W-T version 1.02b.rc5.dt49
Description
The issue is related to a command injection vulnerability in the Remote System Log forwarding function. This function is accessible to unauthenticated users and is located in the adv remotelog.asp page. The vulnerability can be exploited through the
syslogServerAddr parameter.Recommendations
For version 1.02b.rc5.dt49, as a temporary workaround, consider restricting access to the adv remotelog.asp page until a patch is available. Avoid using the
syslogServerAddr parameter in the affected page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Billion 5200W-T