Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.
References
Link | Resource |
---|---|
https://www.tenable.com/security/research/tra-2020-41 | Not Applicable |
https://www.tenable.com/cve/CVE-2020-5756 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2020-07-17 14:15
Updated : 2020-07-22 13:43
NVD link : CVE-2020-5756
Mitre link : CVE-2020-5756
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
grandstream
- gwn7000
- gwn7000_firmware