An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to command injection, allowing remote attackers to execute arbitrary commands, as demonstrated by shell metacharacters in the sysDNSHost parameter.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-03-02T15:06:24
Updated: 2024-08-05T02:39:10.107Z
Reserved: 2020-03-02T00:00:00
Link: CVE-2019-20488
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-03-02T16:15:12.160
Modified: 2024-11-21T04:38:35.990
Link: CVE-2019-20488
Redhat
No data.