ZeroHour

CVE-2018-18879

CVSS 3.0
8.8 high
EPSS
2%p80
Published
()
Modified
Description

In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.

Vendors
columbiaweather
Products
weather microserver firmware
Weakness
CWE-94
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.