vendor:
Atemio AM 520 HD Full HD satellite receiver
by:
Not specified
6.1
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Atemio AM 520 HD Full HD satellite receiver
Affected Version From: Firmware <=2.01
Affected Version To: Not specified
Patch Exists: NO
Related CWE: Not specified
CPE: o:linux:linux_kernel:2.6.32.71
Platforms Tested: GNU/Linux 2.6.32.71, GNU/Linux 3.14-1.17 (armv7l), GNU/Linux 3.14.2 (mips), ATEMIO M46506 revision 990, Atemio 7600 HD STB
Not specified
TitanNit Web Control 2.01 / Atemio 7600 Root Remote Code Execution
The vulnerability in Atemio AM 520 HD Full HD satellite receiver with firmware <=2.01 allows an unauthorized attacker to execute system commands with elevated privileges. By using the 'getcommand' query, the attacker can achieve root access.
Mitigation:
To mitigate this vulnerability, users should update the firmware to a version higher than 2.01 provided by AAF Digital HD Forum | Atelmo GmbH.