CVE-2017-6048
HIGHSatel Iberia SenNet Data Logger and Electricity Meters - Command Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-6048.
Includes Metasploit module auxiliary/scanner/telnet/satel_cmd_exec.
AI-analyzed exploit summary This Metasploit module exploits an OS command injection vulnerability in Satel Iberia SenNet Data Loggers & Electricity Meters, allowing arbitrary command execution as root via a Telnet connection on port 5000.
Description
A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this vulnerability could result in the attacker breaking out of the jailed shell and gaining full access to the system.
Exploits (1)
This Metasploit module exploits an OS command injection vulnerability in Satel Iberia SenNet Data Loggers & Electricity Meters, allowing arbitrary command execution as root via a Telnet connection on port 5000.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H