CVE-2020-7842

Improper Input validation vulnerability exists in Netis Korea D'live AP which could cause arbitrary command injection and execution when the time setting (using ntpServerlp1 parameter) for the users. This affects D'live set-top box AP(WF2429TB) v1.1.10.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netu:wf2429tb_firmware:1.1.10:*:*:*:*:*:*:*
cpe:2.3:h:netu:wf2429tb:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:37

Type Values Removed Values Added
CVSS v2 : 6.0
v3 : 6.6
v2 : 6.0
v3 : 6.4
References () https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35797 - Third Party Advisory () https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35797 - Third Party Advisory

Information

Published : 2020-11-20 16:15

Updated : 2024-11-21 05:37


NVD link : CVE-2020-7842

Mitre link : CVE-2020-7842

CVE.ORG link : CVE-2020-7842


JSON object : View

Products Affected

netu

  • wf2429tb_firmware
  • wf2429tb
CWE
CWE-20

Improper Input Validation