vendor:
FaceSentry Access Control System
by:
7.5
CVSS
HIGH
Remote Command Injection
CWE
Product Name: FaceSentry Access Control System
Affected Version From: Firmware 6.4.8 build 264 (Algorithm A16), Firmware 5.7.2 build 568 (Algorithm A14), Firmware 5.7.0 build 539 (Algorithm A14)
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
FaceSentry Access Control System 6.4.8 Remote Command Injection
FaceSentry suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user via the 'strInIP' and 'strInPort' parameters (POST) in pingTest and tcpPortTest PHP scripts.