ZeroHour

CVE-2018-6940

PoC ×3
CVSS 3.0
6.1 medium
EPSS
3%p86
Published
()
Modified
Description

A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with CSRF.

Vendors
nat32
Products
nat32
Weakness
CWE-79, CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.