Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute.
References
Link | Resource |
---|---|
https://seclists.org/fulldisclosure/2022/Dec/13 | Exploit Mailing List Patch Third Party Advisory |
https://cyberdanube.com/en/authenticated-command-injection-in-intelbras-wifiber-120ac-inmesh/ | Exploit Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-12-25 11:15
Updated : 2023-01-04 18:44
NVD link : CVE-2022-40005
Mitre link : CVE-2022-40005
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
intelbras
- wifiber_120ac_inmesh_firmware
- wifiber_120ac_inmesh