PT-2020-18500 · Aterm · Aterm Wf1200Cr+2
Published
2020-02-21
·
Updated
2020-02-21
·
CVE-2020-5525
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Aterm WF1200C versions 1.2.1 and earlier
Aterm WG1200CR versions 1.2.1 and earlier
Aterm WG2600HS versions 1.3.2 and earlier
Description
The issue allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via the management screen.
Recommendations
For Aterm WF1200C versions 1.2.1 and earlier, update to a version later than 1.2.1.
For Aterm WG1200CR versions 1.2.1 and earlier, update to a version later than 1.2.1.
For Aterm WG2600HS versions 1.3.2 and earlier, update to a version later than 1.3.2.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aterm Wf1200Cr
Aterm Wg1200Cr
Aterm Wg2600Hs