Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
EFM ipTIME A8004T Debug d.cgi httpcon_check_session_url backdoor
Vulnerability Description
A vulnerability was determined in EFM ipTIME A8004T 14.18.2. Affected is the function httpcon_check_session_url of the file /sess-bin/d.cgi of the component Debug Interface. This manipulation of the argument cmd causes backdoor. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
隐藏功能
Vulnerability Title
EFM ipTIME A8004T 安全漏洞
Vulnerability Description
EFM ipTIME A8004T是韩国EFM公司的一款无线路由器。 EFM ipTIME A8004T 14.18.2版本存在安全漏洞,该漏洞源于对文件/sess-bin/d.cgi中函数httpcon_check_session_url的参数cmd的错误操作,可能导致后门。
CVSS Information
N/A
Vulnerability Type
N/A