Metrics
Affected Vendors & Products
Wed, 28 Aug 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Alientechnology alr-f800 Firmware
|
|
CPEs | cpe:2.3:h:alientechnology:alr-f800:-:*:*:*:*:*:*:* cpe:2.3:o:alientechnology:alr-f800_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Alientechnology alr-f800 Firmware
|
Wed, 07 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Alientechnology
Alientechnology alr-f800 |
|
CPEs | cpe:2.3:a:alientechnology:alr-f800:*:*:*:*:*:*:*:* | |
Vendors & Products |
Alientechnology
Alientechnology alr-f800 |
|
Metrics |
ssvc
|
Wed, 07 Aug 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the function popen of the file /var/www/cgi-bin/upgrade.cgi of the component File Name Handler. The manipulation of the argument uploadedFile leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Alien Technology ALR-F800 File Name upgrade.cgi popen os command injection | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-08-07T14:00:08.086Z
Updated: 2024-08-07T15:24:06.724Z
Reserved: 2024-08-07T06:37:55.279Z
Link: CVE-2024-7579
Updated: 2024-08-07T15:23:56.430Z
Status : Analyzed
Published: 2024-08-07T14:15:33.380
Modified: 2024-08-28T18:26:46.117
Link: CVE-2024-7579
No data.