ZeroHour

CVE-2018-16739

PoC
CVSS 3.1
8.8 high
EPSS
1%p62
Published
()
Modified
Description

An issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, and thus execute code arbitrarily with root privileges.

Vendors
abus
Products
tvip 10000 firmware, tvip 10001 firmware, tvip 10005 firmware, tvip 10005a firmware, tvip 10005b firmware, tvip 10050 firmware, tvip 10051 firmware, tvip 10055a firmware, tvip 10055b firmware, tvip 10500 firmware, tvip 10550 firmware, tvip 11000 firmware
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.