PT-2022-6832 · Ce805M · Ce805M

Published

2022-12-13

·

Updated

2022-12-13

CVSS v2.0

9.0

High

AV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CE805M (affected versions not specified)
Description The issue is related to the incorrect management of code generation in the CMD W REG command handler of the CE A protocol implementation in the CE805M data collection and transmission device. This could allow a remote attacker to modify a parameter in such a way that it inserts operating system commands, which would be executed when the application software auto-update is run.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2023-04843

Affected Products

Ce805M