github.com
https://github.com/garis/Fastgate CVE-2019-12489
CRITICAL
Fastweb Fastgate 0.00.81 - Remote Code Execution
Record summary
CVE-2019-12489 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP request, it is possible to inject and execute a command between two & characters in the mount parameter.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBFastweb Fastgate 0.00.81 - Remote Code ExecutionExploitDB exploitby Riccardo GaspariniNot analyzed1 file
Repository PoCs
GitHubgaris/FastgateRepository PoCby garisStars: 2Not analyzed7 files
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-12489 47654exploit
https://www.exploit-db.com/exploits/47654