Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection
Vulnerability Description
A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Linksys RE7000 命令注入漏洞
Vulnerability Description
Linksys RE7000是美国Linksys公司的一款无线网络扩展设备。 Linksys RE7000 2.0.15版本存在命令注入漏洞,该漏洞源于PingTest Handler组件中/cgi-bin/json.cgi?PingTest文件内的platform_event_pingTest函数对参数pingTestIp、pingTestPktSize和pingTestTimes操作不当,可能导致操作系统命令注入,攻击者可远程发起攻击。
CVSS Information
N/A
Vulnerability Type
N/A