CVE-2018-16752
HIGH EXPLOITED IN THE WILDLINK-NET LW-N605R Firmware 12.20.2.1486 - Authenticated Remote Code Execution via Ping HOST Field
Title source: llmExploitation Summary
CVE-2018-16752 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including Nassim Asrir.
AI-analyzed exploit summary This exploit leverages command injection in the HOST field of the ping feature in LW-N605R devices. It authenticates with provided credentials and injects shell metacharacters to execute arbitrary commands.
Description
LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of admin for the admin account may be used in some cases.
Exploits (1)
This exploit leverages command injection in the HOST field of the ping feature in LW-N605R devices. It authenticates with provided credentials and injects shell metacharacters to execute arbitrary commands.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H