CVE-2018-20218

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter in the login form.
References
Link Resource
http://seclists.org/fulldisclosure/2019/Feb/48 Exploit Mailing List Third Party Advisory
https://zxsecurity.co.nz/research.html Not Applicable
http://seclists.org/fulldisclosure/2019/Feb/48 Exploit Mailing List Third Party Advisory
https://zxsecurity.co.nz/research.html Not Applicable
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:teracue:enc-400_hdmi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:teracue:enc-400_hdmi:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:teracue:enc-400_hdmi2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:teracue:enc-400_hdmi2:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:teracue:enc-400_hdsdi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:teracue:enc-400_hdsdi:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:01

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2019/Feb/48 - Exploit, Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2019/Feb/48 - Exploit, Mailing List, Third Party Advisory
References () https://zxsecurity.co.nz/research.html - Not Applicable () https://zxsecurity.co.nz/research.html - Not Applicable

Information

Published : 2019-03-21 16:00

Updated : 2024-11-21 04:01


NVD link : CVE-2018-20218

Mitre link : CVE-2018-20218

CVE.ORG link : CVE-2018-20218


JSON object : View

Products Affected

teracue

  • enc-400_hdsdi
  • enc-400_hdmi2_firmware
  • enc-400_hdmi
  • enc-400_hdmi2
  • enc-400_hdmi_firmware
  • enc-400_hdsdi_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')