evenroute Vulnerabilities and Affected Products
Vulnerabilities associated with iqrouter_firmware.
Products
Clear product- iqrouter_firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-11963CRITICAL | evenroute iqrouter_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux d… CWE-78Apr 21, 2020 | CVSS9.8v3.1 | EPSS3.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |