Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command. This leads to $() command execution.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mitel 6869i 安全漏洞
Vulnerability Description
Mitel 6869i SIP是加拿大敏迪(Mitel)公司的一款功能强大且可扩展的桌面电话。 Mitel 6869i 4.5.0.41版本存在安全漏洞,该漏洞源于 upgrade.html 页面在将标志附加到 busybox ftpget 命令之前未对 username、path参数进行清理,导致命令执行。
CVSS Information
N/A
Vulnerability Type
N/A