Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/plugins/access.ssh/checkInstall.php destServer parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LG N1T1 操作系统命令注入漏洞
Vulnerability Description
LG N1T1是一个动态随机存取存储器。 LG N1T1 10124设备存在操作系统命令注入漏洞,该漏洞源于设备商的网络连接存储中的en/ajp/plugins/access.ssh/checkInstall.php的destServer参数没有经过有效的验证和转义,这允许未经身份验证的攻击者利用该漏洞可以实现系统命令注入而获得root用户权限。
CVSS Information
N/A
Vulnerability Type
N/A