vendor:
3GR-431P
by:
Karn Ganeshen
8,8
CVSS
HIGH
OS Command Injection
78
CWE
Product Name: 3GR-431P
Affected Version From: RTA-A001_02
Affected Version To: RTA-A001_02
Patch Exists: NO
Related CWE: N/A
CPE: h:pixord:3gr-431p
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Vehicle 3G Wi-Fi Router – PIXORD – Multiple Vulnerabilities
PiXORD 3GR-431P 3G Wi-Fi Router is a 3G + GPS + 802.11n (2T2R) wireless router. It supports Internet access via 3G and receives position information from GPS. 3GR-431P also supports two Ethernet ports for LAN connectivity and 802.11n Wi-Fi Access Point for WLAN connectivity. The web application lacks strict input validation and hence vulnerabile to OS command injection.
Mitigation:
Input validation should be done to prevent OS command injection.