ZeroHour

CVE-2020-7594

PoC
CVSS 3.1
7.2 high
EPSS
2%p84
Published
()
Modified
Description

MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metacharacters in the interface JSON field of the ping function.

Vendors
multitech
Products
conduit mtcdt-lvw2-246a firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.