vendor:
WAN Emulator
by:
Brendan Coles
7,5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: WAN Emulator
Affected Version From: 2.3
Affected Version To: 2.3
Patch Exists: NO
Related CWE: N/A
CPE: a:wan_emulator:wan_emulator:2.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2012
WAN Emulator v2.3 Command Execution
This module exploits a command injection vulnerability in WAN Emulator v2.3. The vulnerability exists in the 'cmd' parameter of the '/admin/cmd/' URI, which is accessible to authenticated users. An attacker can inject arbitrary commands, which are executed with root privileges.
Mitigation:
Restrict access to the vulnerable URI and ensure that user input is properly sanitized.