vendor:
TD5130.2
by:
João Teles
7.2
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: TD5130.2
Affected Version From: TD5130v2
Affected Version To: TD5130v2
Patch Exists: NO
Related CWE: CVE-2019-18396
CPE: o:technicolor:td5130v2
Platforms Tested:
2019
Technicolor TD5130.2 – Remote Command Execution
The Technicolor TD5130.2 router is vulnerable to remote command execution. This allows an attacker to execute arbitrary commands on the device by sending a crafted HTTP POST request to the /mnt_ping.cgi endpoint. The vulnerability exists in the firmware version OI_Fw_V20 and has been assigned CVE-2019-18396.
Mitigation:
To mitigate this vulnerability, it is recommended to update the firmware to a patched version.