CVE-2018-20122

The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary that is vulnerable to a command injection vulnerability that can be exploited to achieve remote code execution with root privileges. No authentication is required in order to trigger the vulnerability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:fastweb:fastgate_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fastweb:fastgate:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:00

Type Values Removed Values Added
References () http://www.horizonsecurity.it/advisories/?a=12&title=Fastweb+FastGate+router+101b+Remote+code+execution++CVE201820122 - Third Party Advisory () http://www.horizonsecurity.it/advisories/?a=12&title=Fastweb+FastGate+router+101b+Remote+code+execution++CVE201820122 - Third Party Advisory

Information

Published : 2019-02-21 14:29

Updated : 2024-11-21 04:00


NVD link : CVE-2018-20122

Mitre link : CVE-2018-20122

CVE.ORG link : CVE-2018-20122


JSON object : View

Products Affected

fastweb

  • fastgate_firmware
  • fastgate
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')