漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Four-Faith Industrial Router adjust_sys_time OS Command Injection
Vulnerability Description
The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when modifying the system time via apply.cgi. Additionally, this firmware version has default credentials which, if not changed, would effectively change this vulnerability into an unauthenticated and remote OS command execution issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Four-Faith F3x24和Four-Faith F3x36 安全漏洞
Vulnerability Description
Four-Faith F3x24和Four-Faith F3x36都是中国四信(Four-Faith)公司的一款便携式无线移动路由器。 Four-Faith F3x24和Four-Faith F3x36存在安全漏洞。攻击者利用该漏洞可以通过 apply.cgi 修改系统时间时通过 HTTP 执行任意操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A