PT-2020-13070 · Beeline · Beeline Smart Box

Published

2020-04-29

·

Updated

2020-05-07

·

CVE-2020-12246

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Beeline Smart Box version 2.0.38
Description The issue allows OS command injection via the "Advanced settings > Other > Diagnostics" feature. Specifically, it affects the ping ipaddr parameter in the Ping function, the nslookup ipaddr parameter in the Nslookup function, or the traceroute ipaddr parameter in the Traceroute function.
Recommendations For Beeline Smart Box version 2.0.38, as a temporary workaround, consider restricting access to the "Advanced settings > Other > Diagnostics" feature until a patch is available. Avoid using the ping ipaddr, nslookup ipaddr, and traceroute ipaddr parameters in the affected functions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12246

Affected Products

Beeline Smart Box