Showing 1 vulnerability on this page for vr-3033_firmware

Signals CISA KEV Ransomware Nuclei
Comtrend vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

comtrend vr-3033_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.

CWE-78Mar 5, 2020
CVSS8.8v3.1EPSS76.8%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX