ZeroHour

CVE-2017-12576

CVSS 3.0
7.2 high
EPSS
2%p81
Published
()
Modified
Description

An issue was discovered on the PLANEX CS-QR20 1.30. A hidden and undocumented management page allows an attacker to execute arbitrary code on the device when the user is authenticated. The management page was used for debugging purposes, once you login and access the page directly (/admin/system_command.asp), you can execute any command.

Vendors
planex
Products
cs-qr20 firmware
Weakness
CWE-668
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.