Description
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. The device has a command-injection vulnerability in the web management UI on NAS settings page "/cgi-bin/nasset.cgi". An attacker can send a crafted HTTP POST request to execute arbitrary code. Authentication is required before executing the attack.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-4145 | An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. The device has a command-injection vulnerability in the web management UI on NAS settings page "/cgi-bin/nasset.cgi". An attacker can send a crafted HTTP POST request to execute arbitrary code. Authentication is required before executing the attack. |
References
| Link | Providers |
|---|---|
| http://seclists.org/fulldisclosure/2018/Aug/29 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T18:43:56.315Z
Reserved: 2017-08-05T00:00:00.000Z
Link: CVE-2017-12573
No data.
Status : Modified
Published: 2018-08-24T19:29:00.533
Modified: 2024-11-21T03:09:46.727
Link: CVE-2017-12573
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD