vendor:
CGN3ACSMR
by:
Dolev Farhi
9,8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: CGN3ACSMR
Affected Version From: 4.5.8.16
Affected Version To: 4.5.8.16
Patch Exists: NO
Related CWE: N/A
CPE: h:hitron:cgn3acsmr
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Hitron Router (CGN3ACSMR) – Remote Code Execution
Hitron routers provide an interface to test connectivity (ping, tracert) via the graphical user interface of the router (Management UI). This interface is vulnerable to code injection using the && argument after the IP address.
Mitigation:
Disable the Management UI or restrict access to it.