Alien Technology ALR-F800 File Name upgrade.cgi popen os command injection
Published Aug 7, 2024
5.3
MEDIUMCVSS 4.0
EPSS 8.38%
Description
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the function popen of the file /var/www/cgi-bin/upgrade.cgi of the component File Name Handler. The manipulation of the argument uploadedFile leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
Affected
- 19.10.0
- 19.10.1
- 19.10.10
- 19.10.11
- 19.10.12
- 19.10.13
- 19.10.14
- 19.10.15
- 19.10.16
- 19.10.17
- 19.10.18
- 19.10.19
- 19.10.2
- 19.10.20
- 19.10.21
- 19.10.22
- 19.10.23
- 19.10.24
- 19.10.3
- 19.10.4
- 19.10.5
- 19.10.6
- 19.10.7
- 19.10.8
- 19.10.9
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Alien Technology | ALR-F800 | unknown | Affected
|
- ≤ 19.10.24
Running on/with
- n/a
-
Affected
- ≥ 0, < 19.10.24.00
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Alientechnology | Alr-F800 | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48476 Advisory
- https://github.com/Push3AX/vul/blob/main/Alien%20Technology%20/ALR-F800.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.273859 signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry
- https://vuldb.com/?id.273859 vdb-entrytechnical-descriptionPermissions RequiredThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.382470 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48476 | Advisory | |
| https://github.com/Push3AX/vul/blob/main/Alien%20Technology%20/ALR-F800.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.273859 | signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?id.273859 | vdb-entrytechnical-descriptionPermissions RequiredThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.382470 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data