CVE-2015-6024
CRITICALNetCommWireless HSPA 3G10WVE - Command Injection
Title source: llmDescription
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the DIA_IPADDRESS parameter.
Exploits (1)
References (6)
Scores
CVSS v3
9.8
EPSS
0.4929
EPSS Percentile
97.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-77
Status
published
Products (1)
netcommwireless/hspa_3g10wve_firmware
3g10wve-l101-s306ets-c01_r03
Published
Feb 09, 2017
Tracked Since
Feb 18, 2026