vendor:
WIFI Repeater BE126
by:
Hay Mizrachi, Omer Kaspi
8,8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: WIFI Repeater BE126
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: YES
Related CWE: CVE-2017-13713
CPE: a:twsz:wifi_repeater_be126
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows/Ubuntu 16.04
2017
WIFI Repeater BE126 – Remote Code Execution
HTTP POST request that contains user parmater which can give us to run Remote Code Execution to the device. The parameter is not sanitized at all, which cause him to be vulnerable.
Mitigation:
Sanitize user input to prevent Remote Code Execution.