The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via authenticated code injection over the network.
References
Link | Resource |
---|---|
https://podalirius.net/cves/2020-16148/ | Exploit Third Party Advisory |
https://podalirius.net/en/cves/2020-16148/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Information
Published : 2020-09-24 07:15
Updated : 2022-04-28 11:21
NVD link : CVE-2020-16148
Mitre link : CVE-2020-16148
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
telmat
- educ\@box
- git\@box_firmware
- accesslog_firmware
- accesslog
- git\@box
- educ\@box_firmware