vendor:
S9922XL and S9922L
by:
LiquidWorm
7,5
CVSS
HIGH
Remote Command Execution (RCE)
78
CWE
Product Name: S9922XL and S9922L
Affected Version From: 16.10.3
Affected Version To: 16.10.3
Patch Exists: YES
Related CWE: N/A
CPE: h:ricon_mobile:s9922xl-lte
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: GNU/Linux 2.6.36 (mips), WEB-ROUTER
2021
Ricon Industrial Cellular Router S9922XL – Remote Command Execution (RCE)
The router suffers from an authenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands as the admin (root) user via the 'ping_server_ip' POST parameter. Also vulnerable to Heartbleed.
Mitigation:
Ensure that the router is running the latest version of the firmware and that all security patches are applied.