PT-2020-8532 · Green Packet · Green Packet Wimax Dv-360
Published
2020-12-31
·
Updated
2021-01-06
·
CVE-2018-14067
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Green Packet WiMax DV-360 version 2.10.14-g1.0.6.1
Description:
The issue allows for Command Injection, enabling unauthenticated remote command execution. This can be achieved by sending a crafted payload to the HTTPS port. The problem arises because lighttpd listens on all network interfaces, including the external Internet, by default.
Recommendations:
For Green Packet WiMax DV-360 version 2.10.14-g1.0.6.1, consider restricting access to the HTTPS port or configuring lighttpd to only listen on internal network interfaces to minimize the risk of exploitation.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Green Packet Wimax Dv-360