vendor:
PMG5318-B20A
by:
Karn Ganeshen
9,8
CVSS
CRITICAL
OS Command Injection
20
CWE
Product Name: PMG5318-B20A
Affected Version From: Firmware version V100AANC0b5
Affected Version To: Firmware version V100AANC0b5
Patch Exists: YES
Related CWE: CVE-2015-6018
CPE: h:zyxel:pmg5318-b20a
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
ZyXEL PMG5318-B20A OS Command Injection Vulnerability
The diagnostic ping function's PingIPAddr parameter in the ZyXEL PMG5318-B20A, firmware version V100AANC0b5, does not properly validate user input. An attacker can execute arbitrary commands as root.
Mitigation:
Input validation should be done to prevent OS command injection.