CVE-2017-16934

CVE-2017-16934

The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a change_password.csp request, which supports a "<%%25call system.exec:" string in the passwd parameter.

Source: CVE-2017-16934

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다