An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP request, it is possible to inject and execute a command between two & characters in the mount parameter.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-11-26T14:42:40
Updated: 2024-08-04T23:24:38.462Z
Reserved: 2019-05-30T00:00:00
Link: CVE-2019-12489
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2019-11-26T15:15:12.050
Modified: 2020-08-24T17:37:01.140
Link: CVE-2019-12489
Redhat
No data.