CVE-2020-8963

TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel or srtime parameter.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:timetoolsltd:sr9850_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sr9850:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:timetoolsltd:sr9750_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sr9750:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:timetoolsltd:sc9705_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sc9705:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:timetoolsltd:sr9210_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sr9210:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:timetoolsltd:sc9205_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sc9205:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:timetoolsltd:sr7110_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sr7110:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:timetoolsltd:sc7105_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sc7105:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:timetoolsltd:t100_firmware:1.0.003:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:t100:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:timetoolsltd:t300_firmware:1.0.003:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:t300:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:timetoolsltd:t550_firmware:1.0.003:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:t550:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:39

Type Values Removed Values Added
References () https://sku11army.blogspot.com/2020/02/timetools-sr-sc-series-network-time.html - Exploit, Third Party Advisory () https://sku11army.blogspot.com/2020/02/timetools-sr-sc-series-network-time.html - Exploit, Third Party Advisory

Information

Published : 2020-02-13 03:15

Updated : 2024-11-21 05:39


NVD link : CVE-2020-8963

Mitre link : CVE-2020-8963

CVE.ORG link : CVE-2020-8963


JSON object : View

Products Affected

timetoolsltd

  • sc9705_firmware
  • sr9210_firmware
  • sc7105_firmware
  • t300
  • sc9205
  • t550_firmware
  • sr7110
  • sc9205_firmware
  • sc7105
  • t550
  • sc9705
  • t100
  • sr9750_firmware
  • t100_firmware
  • sr9750
  • sr9850_firmware
  • sr7110_firmware
  • sr9210
  • sr9850
  • t300_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')