Unauthenticated Command Injection EG7035-M11 Series
Published Mar 1, 2023
9.8
CRITICALCVSS 3.1
EPSS 1.13%
Description
Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods have been tested and validated by a 3rd party analyst and have been confirmed exploitable special thanks to Lionel Musonza for the discovery.
Affected products
-
- Version 0StatusaffectedConstraints<=BCE-ODU-1.0.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Baicells | n/a | unaffected |
|
- ≤ bce-odu-1.0.8
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Baicells recommends that all customers currently running an earlier version of BCE-ODU-1.0.8 upgrade their product to the BaiCE_BM_2.5.26 firmware.
References (3)
- https://community.na.baicells.com/t/baice-bm-2-5-26-new-cpe-software-has-been-released/1756 patchrelease-notesRelease Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-23384 Advisory
- https://img.baicells.com//Upload/20220524/FILE/BaiCE_BM_2.5.26_NA.bin.bin patchProduct
| Link | Providers | Tags |
|---|---|---|
| https://community.na.baicells.com/t/baice-bm-2-5-26-new-cpe-software-has-been-released/1756 | patchrelease-notesRelease Notes | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-23384 | Advisory | |
| https://img.baicells.com//Upload/20220524/FILE/BaiCE_BM_2.5.26_NA.bin.bin | patchProduct |
Change history (0)
No recorded changes yet.