PT-2024-22850 · Kasda · Kasda Linksmart Router Kw6512
Quartzdust
·
Published
2024-11-20
·
Updated
2024-11-27
·
CVE-2024-29292
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kasda LinkSmart Router KW6512 versions <= v1.3
Description
The issue is related to Multiple OS Command Injection vulnerabilities. An authenticated remote attacker can execute arbitrary OS commands via various cgi parameters.
Recommendations
For Kasda LinkSmart Router KW6512 versions <= v1.3, update to a version later than v1.3 to resolve the issue.
As a temporary workaround, consider restricting access to the cgi parameters that allow OS command execution until a patch is available.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kasda Linksmart Router Kw6512