packetstormsecurity.com
http://packetstormsecurity.com/files/155296/Technicolor-TD5130.2-Remote-Command-Execution.html CVE-2019-18396
HIGH
technicolor td5130v2_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2019-18396 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping module in the Web Interface in OI_Fw_V20 allows remote attackers to execute arbitrary OS commands in the pingAddr parameter to mnt_ping.cgi. NOTE: This may overlap CVE-2017–14127.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 13, 2019 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
td5130v2_firmwareBrowse technicolor / td5130v2_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBTechnicolor TD5130.2 - Remote Command ExecutionExploitDB exploitby João TelesNot analyzed1 file
References
5medium.com
https://medium.com/%40c4pt41nnn/cve-2019-18396-command-injection-in-technicolor-router-da5dd2134052 medium.com
https://medium.com/@c4pt41nnn/cve-2019-18396-command-injection-in-technicolor-router-da5dd2134052 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-18396 twitter.com
https://www.twitter.com/c4pt41nnn