Description
The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly validate ping command arguments, which allows remote authenticated users to execute OS commands as root via shell metacharacters in the Target_IP parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-7853 | The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly validate ping command arguments, which allows remote authenticated users to execute OS commands as root via shell metacharacters in the Target_IP parameter. |
References
| Link | Providers |
|---|---|
| https://gbti.pl/public/10_2019-compal.txt |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:40:15.797Z
Reserved: 2019-10-11T00:00:00.000Z
Link: CVE-2019-17499
No data.
Status : Modified
Published: 2019-10-11T11:15:10.107
Modified: 2024-11-21T04:32:23.017
Link: CVE-2019-17499
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD