CVE-2016-10312

CRITICAL

Jensenofscandinavia Al3g Firmware - Command Injection

Title source: rule
STIX 2.1

Description

Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to execute arbitrary commands via shell metacharacters to certain /goform/* pages.

References (1)

Core 1
Core References
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://www.riskbasedsecurity.com/research/RBS-2016-004.pdf

Scores

CVSS v3 9.8
EPSS 0.0337
EPSS Percentile 87.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (3)
jensenofscandinavia/al3g_firmware 2.23m
jensenofscandinavia/al5000ac_firmware 1.13
jensenofscandinavia/al59300_firmware 1.04
Published Apr 03, 2017
Tracked Since Feb 18, 2026