CVE-2023-24796

Password vulnerability found in Vinga WR-AC1200 81.102.1.4370 and before allows a remote attacker to execute arbitrary code via the password parameter at the /goform/sysTools and /adm/systools.asp endpoints.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:vinga:wr-ac1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:vinga:wr-ac1200:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:48

Type Values Removed Values Added
References () https://gist.github.com/yinfei6/3664387cb5b66b68c7eff4bfdb51b2d6 - Third Party Advisory () https://gist.github.com/yinfei6/3664387cb5b66b68c7eff4bfdb51b2d6 - Third Party Advisory

Information

Published : 2023-04-26 13:15

Updated : 2024-11-21 07:48


NVD link : CVE-2023-24796

Mitre link : CVE-2023-24796

CVE.ORG link : CVE-2023-24796


JSON object : View

Products Affected

vinga

  • wr-ac1200
  • wr-ac1200_firmware