Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/huzaifahussain98/CVE-2020-23584 |
|
History
Fri, 25 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-25T20:44:15.376Z
Reserved: 2020-08-13T00:00:00.000Z
Link: CVE-2020-23584
Updated: 2024-08-04T14:58:15.186Z
Status : Modified
Published: 2022-11-23T02:15:09.070
Modified: 2025-04-25T21:15:17.223
Link: CVE-2020-23584
No data.
OpenCVE Enrichment
No data.
Weaknesses