CVE-2019-19148

Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2020.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tellabs:optical_line_terminal_1150_firmware:ont709.2.50.12:*:*:*:*:*:*:*
cpe:2.3:h:tellabs:optical_line_terminal_1150:fp29.2_015873:*:*:*:*:*:*:*

History

21 Nov 2024, 04:34

Type Values Removed Values Added
References () https://docs.tellabs.com/articles/#%21vulnerability-response/cve-2019-19148 - () https://docs.tellabs.com/articles/#%21vulnerability-response/cve-2019-19148 -
References () https://github.com/ellwoodthewood/tellabs_rce - Exploit, Third Party Advisory () https://github.com/ellwoodthewood/tellabs_rce - Exploit, Third Party Advisory

07 Nov 2023, 03:07

Type Values Removed Values Added
References
  • {'url': 'https://docs.tellabs.com/articles/#!vulnerability-response/cve-2019-19148', 'name': 'https://docs.tellabs.com/articles/#!vulnerability-response/cve-2019-19148', 'tags': [], 'refsource': 'CONFIRM'}
  • () https://docs.tellabs.com/articles/#%21vulnerability-response/cve-2019-19148 -

Information

Published : 2020-03-20 18:15

Updated : 2024-11-21 04:34


NVD link : CVE-2019-19148

Mitre link : CVE-2019-19148

CVE.ORG link : CVE-2019-19148


JSON object : View

Products Affected

tellabs

  • optical_line_terminal_1150_firmware
  • optical_line_terminal_1150
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')