CVE-2015-6024

CRITICAL

NetCommWireless HSPA 3G10WVE - Command Injection

Title source: llm

Description

ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the DIA_IPADDRESS parameter.

Exploits (1)

exploitdb WORKING POC
by Bhadresh Patel · textwebappscgi
https://www.exploit-db.com/exploits/39762

Scores

CVSS v3 9.8
EPSS 0.4929
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (1)
netcommwireless/hspa_3g10wve_firmware 3g10wve-l101-s306ets-c01_r03
Published Feb 09, 2017
Tracked Since Feb 18, 2026