The systool_server in PAX Technology A930 PayDroid 7.1.1 Virgo V04.4.02 20211201 fails to check for dollar signs or backticks in user supplied commands, leading to to arbitrary command execution as root.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-12-16 14:15
Updated : 2023-02-28 16:15
NVD link : CVE-2022-26582
Mitre link : CVE-2022-26582
JSON object : View
CWE
Products Affected
paxtechnology
- paydroid
- a930