An issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181105.bin. A shell command injection occurs by editing the description of an ISP file. The file network/isp/isp_update_edit.php does not properly validate user input, which leads to shell command injection via the des parameter.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-03-17T19:04:54
Updated: 2024-08-04T20:46:46.242Z
Reserved: 2019-02-04T00:00:00
Link: CVE-2019-7383
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-03-21T16:01:11.610
Modified: 2024-11-21T04:48:06.723
Link: CVE-2019-7383
Redhat
No data.