CVE-2018-6388

HIGH

Iball Ib-wra150n Firmware - OS Command Injection

Title source: rule
STIX 2.1

Description

iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping test arguments on the Diagnostics page.

Exploits (1)

exploitdb WRITEUP
by SecuriTeam · webappshardware
https://www.exploit-db.com/exploits/44043

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://blogs.securiteam.com/index.php/archives/3654

Scores

CVSS v3 8.8
EPSS 0.0711
EPSS Percentile 91.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
iball/ib-wra150n_firmware 1.2.6
Published Jan 29, 2018
Tracked Since Feb 18, 2026