vendor:
EMG2926
by:
Fluffy Huffy (trevor Hough)
8,8
CVSS
HIGH
OS Command Injection
78
CWE
Product Name: EMG2926
Affected Version From: EMG2926 - V1.00(AAQT.4)b8
Affected Version To: EMG2926 - V1.00(AAQT.4)b8
Patch Exists: YES
Related CWE: CVE-2017-6884
CPE: h:zyxel:emg2926
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2017
Zyxel, EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection
A malicious user may exploit numerous vectors to execute arbitrary commands on the router. An example of an exploit is a reverse shell, which can be used to gain access to the router, as well as a dump password file, which can be used to gain access to the router's credentials.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in system commands.