CVE-2020-7594
PoC —CVSS 3.1
7.2 high
EPSS
2%p84
Published
()
Modified
Description
MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metacharacters in the interface JSON field of the ping function.
- Vendors
- multitech
- Products
- conduit mtcdt-lvw2-246a firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.