Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute.
References
Link | Resource |
---|---|
https://cyberdanube.com/en/authenticated-command-injection-in-intelbras-wifiber-120ac-inmesh/ | Exploit Patch Third Party Advisory |
https://seclists.org/fulldisclosure/2022/Dec/13 | Exploit Mailing List Patch Third Party Advisory |
https://cyberdanube.com/en/authenticated-command-injection-in-intelbras-wifiber-120ac-inmesh/ | Exploit Patch Third Party Advisory |
https://seclists.org/fulldisclosure/2022/Dec/13 | Exploit Mailing List Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 07:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://cyberdanube.com/en/authenticated-command-injection-in-intelbras-wifiber-120ac-inmesh/ - Exploit, Patch, Third Party Advisory | |
References | () https://seclists.org/fulldisclosure/2022/Dec/13 - Exploit, Mailing List, Patch, Third Party Advisory |
Information
Published : 2022-12-25 19:15
Updated : 2024-11-21 07:20
NVD link : CVE-2022-40005
Mitre link : CVE-2022-40005
CVE.ORG link : CVE-2022-40005
JSON object : View
Products Affected
intelbras
- wifiber_120ac_inmesh_firmware
- wifiber_120ac_inmesh
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')