Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cypress Solutions CTM-200 2.7.1 Root Remote OS Command Injection via Firmware Upgrade
Vulnerability Description
Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script that allows remote attackers to execute shell commands. Attackers can exploit the 'fw_url' parameter in the ctm-config-upgrade.sh script to inject and execute arbitrary commands with root privileges.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Cypress Solutions CTM-200 操作系统命令注入漏洞
Vulnerability Description
Cypress Solutions CTM-200是Cypress Solutions公司的一款无线网关。 Cypress Solutions CTM-200 2.7.1版本存在操作系统命令注入漏洞,该漏洞源于固件升级脚本fw_url参数存在经过身份验证的命令注入,可能导致远程攻击者以root权限执行shell命令。
CVSS Information
N/A
Vulnerability Type
N/A