CVE-2019-25487
CRITICAL SEVERITYCVSS Score & Metrics
Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Description
SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests with the sysCmd parameter containing shell commands to execute code on the device with router privileges.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-639
Source
NVD
Vendor
Sapido
Product
RB-1732
Discussion (0)
Add Comment
No comments yet. Be the first!