PT-2019-9650 · Cerio · Cerio Dt-300N
Published
2019-06-18
·
Updated
2019-06-18
·
CVE-2018-18852
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cerio DT-300N versions 1.1.6 through 1.1.12
Description
The issue arises from improper input validation in the web-interface PING feature, which uses Save.cgi to execute a ping command, allowing OS command injection. This has been exploited in the wild.
Recommendations
For Cerio DT-300N versions 1.1.6 through 1.1.12, consider disabling the Save.cgi functionality related to the PING feature as a temporary workaround until a patch is available. Restrict access to the web-interface PING feature to minimize the risk of exploitation.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cerio Dt-300N