In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vulnerable parameters], are not properly sanitized after being submitted to the web interface in a POST request. With specially crafted parameters, it is possible to inject a an OS command which will be executed with root privileges, as the web interface, and all processes on the device, run as root.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-35319 In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vulnerable parameters], are not properly sanitized after being submitted to the web interface in a POST request. With specially crafted parameters, it is possible to inject a an OS command which will be executed with root privileges, as the web interface, and all processes on the device, run as root.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T06:40:47.448Z

Reserved: 2022-05-02T00:00:00

Link: CVE-2022-30105

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-18T16:15:08.850

Modified: 2024-11-21T07:02:10.760

Link: CVE-2022-30105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.