PT-2022-26440 · Generex · Generex Cs141

CVE-2022-42457

·

Published

2022-10-06

·

Updated

2022-11-10

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Generex CS141 versions 2.08 through 2.10
Description The issue allows remote command execution by administrators via a web interface that reaches run update in /usr/bin/gxserve-update.sh. This can occur, for example, via a reverse shell installed by install.sh.
Recommendations For versions 2.08 through 2.10, update to a version later than 2.10 to resolve the issue. As a temporary workaround, consider restricting access to the run update function in /usr/bin/gxserve-update.sh until a patch is available. Avoid using the install.sh script in the affected API endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-42457

Affected Products

Generex Cs141