Showing 1 vulnerability on this page for iqrouter_firmware

Signals CISA KEV Ransomware Nuclei
evenroute vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

evenroute iqrouter_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux d

CWE-78Apr 21, 2020
CVSS9.8v3.1EPSS3.15%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX