Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T11:23:08.841Z

Reserved: 2018-10-30T00:00:00

Link: CVE-2018-18852

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-18T15:15:11.267

Modified: 2024-11-21T03:56:44.873

Link: CVE-2018-18852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.