CRITICAL
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below
Published Mar 17, 2019
9.8
CRITICALCVSS 3.0
EPSS 10.73%
Description
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter in the login form.
Affected products
No data.
Configuration 1
AND
- ≤ 2.56
Running on/with
- n/a
Configuration 2
AND
- ≤ 2.56
Running on/with
- n/a
Configuration 3
AND
- ≤ 2.56
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://seclists.org/fulldisclosure/2019/Feb/48 x_refsource_MISCExploitMailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-12785 Advisory
- https://zxsecurity.co.nz/research.html x_refsource_MISCNot Applicable
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/fulldisclosure/2019/Feb/48 | x_refsource_MISCExploitMailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-12785 | Advisory | |
| https://zxsecurity.co.nz/research.html | x_refsource_MISCNot Applicable |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 17, 2019
Updated Aug 5, 2024
Reserved Dec 19, 2018
Link CVE-2018-20218
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2018-12785 Assigner mitre
Published Mar 17, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2018-12785