vendor:
NAT32
by:
hyp3rlinx
6.1
CVSS
MEDIUM
Remote Command Execution
78
CWE
Product Name: NAT32
Affected Version From: NAT32 Build 22284
Affected Version To: NAT32 Build 22284
Patch Exists: YES
Related CWE: CVE-2018-6940
CPE: a:nat32:nat32:22284
Platforms Tested: Windows
2018
NAT32 Remote Command Execution
NAT32 listens on Port 8080 for its Web interface. If the 'Password Checking' feature is not enabled, remote attackers can potentially execute arbitrary commands. If the 'Password Checking' feature is enabled, remote attackers can potentially issue arbitrary commands exploiting a Cross Site Scripting vulnerability. NAT32 also implements BASIC authentication which pass BASE64 Encoded credentials that can be easily revealed if sniffed on the network.
Mitigation:
Enable 'Password Checking' feature and ensure that it is properly configured. Regularly update NAT32 to the latest version to patch any existing vulnerabilities.