Record summary

CVE-2019-18396 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit.

Description

An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping module in the Web Interface in OI_Fw_V20 allows remote attackers to execute arbitrary OS commands in the pingAddr parameter to mnt_ping.cgi. NOTE: This may overlap CVE-2017–14127.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 13, 2019 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBTechnicolor TD5130.2 - Remote Command ExecutionExploitDB exploitby João TelesNot analyzed1 file
ExploitDB

PoC details

References

5