Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Four-Faith Industrial Router adjust_sys_time OS Command Injection
Vulnerability Description
The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when modifying the system time via apply.cgi. Additionally, this firmware version has default credentials which, if not changed, would effectively change this vulnerability into an unauthenticated and remote OS command execution issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Four-Faith F3x24和Four-Faith F3x36 安全漏洞
Vulnerability Description
Four-Faith F3x24和Four-Faith F3x36都是中国四信(Four-Faith)公司的一款便携式无线移动路由器。 Four-Faith F3x24和Four-Faith F3x36存在安全漏洞。攻击者利用该漏洞可以通过 apply.cgi 修改系统时间时通过 HTTP 执行任意操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A