vendor:
by:
Davy Douhine, Florent Montel, Frederic Cikala
9.8
CVSS
CRITICAL
Arbitrary Command Execution
CWE
Product Name:
Affected Version From: Firmware <= 1.11.0.12
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2017-5173, CVE-2017-5174
CPE:
Platforms Tested: Unix
2017
Geutebruck testaction.cgi Remote Command Execution
This module exploits a an arbitrary command execution vulnerability. The vulnerability exists in the /uapi-cgi/viewer/testaction.cgi page and allows an anonymous user to execute arbitrary commands with root privileges. Firmware <= 1.11.0.12 are concerned. Tested on 5.02024 G-Cam/EFD-2250 running 1.11.0.12 firmware.
Mitigation:
Update firmware to version 1.11.0.13 or later.