PT-2022-26440 · Generex · Generex Cs141
Published
2022-10-06
·
Updated
2022-11-10
·
CVE-2022-42457
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Generex CS141 versions 2.08 through 2.10
Description
The issue allows remote command execution by administrators via a web interface that reaches
run update in /usr/bin/gxserve-update.sh. This can occur, for example, via a reverse shell installed by install.sh.Recommendations
For versions 2.08 through 2.10, update to a version later than 2.10 to resolve the issue.
As a temporary workaround, consider restricting access to the
run update function in /usr/bin/gxserve-update.sh until a patch is available.
Avoid using the install.sh script in the affected API endpoint until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Generex Cs141