PT-2020-19802 · Kt · Kt Slim Egg Iml500+1

Inhyeong Lee

·

Published

2020-05-07

·

Updated

2020-05-14

·

CVE-2020-7805

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KT Slim egg IML500 versions R7283, R8112, R8424 KT Slim egg IML520 versions R8112, R8368, R8411
Description The issue discovered is a command injection, allowing attackers to execute arbitrary OS commands. This affects the wifi device functionality.
Recommendations For KT Slim egg IML500 versions R7283, R8112, R8424, consider disabling the command execution functionality until a patch is available. For KT Slim egg IML520 versions R8112, R8368, R8411, restrict access to the vulnerable wifi device module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7805

Affected Products

Kt Slim Egg Iml500
Kt Slim Egg Iml520