PT-2019-18570 · Raisecom · Raisecom Iscom Ht803G-W+2

CVE-2019-7385

·

Publicado

2019-03-17

·

Atualizado

2023-02-01

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with firmware version ISCOMHT803G-U 2.0.0 140521 R4.1.47.002 or below
Description An authenticated shell command injection issue has been discovered. The values of the newpass and confpass parameters in the /bin/WebMGR endpoint are used in a system call in the firmware. Because there is no user input validation, this leads to authenticated code execution on the device.
Recommendations For Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with firmware version ISCOMHT803G-U 2.0.0 140521 R4.1.47.002 or below, consider updating to a newer firmware version to resolve the issue. As a temporary workaround, restrict access to the /bin/WebMGR endpoint to minimize the risk of exploitation. Avoid using the newpass and confpass parameters in the affected endpoint until the issue is resolved.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-7385

Produtos afetados

Raisecom Iscom Ht803G Gpon
Raisecom Iscom Ht803G-1Ge
Raisecom Iscom Ht803G-W