PT-2025-31686 · Raidsonic · Ib-Nas4220+1

CVE-2013-10049

·

Publicado

2025-08-01

·

Atualizado

2025-08-01

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Raidsonic NAS devices versions IB-NAS5220 and IB-NAS4220
Description An OS command injection issue exists due to improper sanitization of user-supplied input. The timeHandler.cgi API endpoint is vulnerable, allowing remote attackers to inject arbitrary shell commands via the timeZone parameter in a POST request. The endpoint is unauthenticated.
Recommendations Apply input validation and sanitization to the timeZone parameter of the timeHandler.cgi endpoint.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-10049

Produtos afetados

Ib-Nas4220
Ib-Nas5220