PT-2019-9650 · Cerio · Cerio Dt-300N

Published

2019-06-18

·

Updated

2019-06-18

·

CVE-2018-18852

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cerio DT-300N versions 1.1.6 through 1.1.12
Description The issue arises from improper input validation in the web-interface PING feature, which uses Save.cgi to execute a ping command, allowing OS command injection. This has been exploited in the wild.
Recommendations For Cerio DT-300N versions 1.1.6 through 1.1.12, consider disabling the Save.cgi functionality related to the PING feature as a temporary workaround until a patch is available. Restrict access to the web-interface PING feature to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18852

Affected Products

Cerio Dt-300N