Netis NX10 固件版本 V4.0.1.5808 和 V3.0.0.4142 中的 ping 诊断处理程序存在操作系统命令注入漏洞。已认证的管理员可以通过向 参数注入内容,以 root 身份执行任意 shell 命令。该参数被直接插入到通过 执行的 shell 命令中,其不完整的拒绝列表仅阻止了空格、管道符、分号和 &(ampersand)符号,但仍留有命令替换和替代字段分隔符扩展的攻击面可供利用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Netis Systems | NX10 | 4.0.1.5808 |
affected |
3.0.0.4142 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Netis Systems | NX10 | 4.0.1.5808 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet