An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, there are some diagnostic tests available that are not displayed on the webpage; these are only accessible by crafting a POST request with a program like cURL. There is one test accessible via cURL that does not properly sanitize user input, allowing an attacker to execute shell commands as the root user.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://blog.iancaling.com/post/160596244178 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-05-21T21:00:00
Updated: 2024-08-05T16:55:22.271Z
Reserved: 2017-05-21T00:00:00
Link: CVE-2017-9135
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-05-21T21:29:00.330
Modified: 2024-11-21T03:35:24.140
Link: CVE-2017-9135
Redhat
No data.