PT-2020-19802 · Kt · Kt Slim Egg Iml500+1
Inhyeong Lee
·
Published
2020-05-07
·
Updated
2020-05-14
·
CVE-2020-7805
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
KT Slim egg IML500 versions R7283, R8112, R8424
KT Slim egg IML520 versions R8112, R8368, R8411
Description
The issue discovered is a command injection, allowing attackers to execute arbitrary OS commands. This affects the wifi device functionality.
Recommendations
For KT Slim egg IML500 versions R7283, R8112, R8424, consider disabling the command execution functionality until a patch is available.
For KT Slim egg IML520 versions R8112, R8368, R8411, restrict access to the vulnerable wifi device module to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kt Slim Egg Iml500
Kt Slim Egg Iml520