vendor:
OpenNetAdmin
by:
mattpascoe
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: OpenNetAdmin
Affected Version From: v18.1.1
Affected Version To: v18.1.1
Patch Exists: YES
Related CWE: N/A
CPE: a:opennetadmin:opennetadmin:18.1.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2019
OpenNetAdmin v18.1.1 RCE
OpenNetAdmin v18.1.1 is vulnerable to Remote Code Execution. An attacker can send a malicious payload to the vulnerable server to execute arbitrary code. The payload is sent via a POST request to the vulnerable server.
Mitigation:
Upgrade to the latest version of OpenNetAdmin v18.1.1 or later.