nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25483 CVE-2019-25483
HIGH
Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k Restricted Shell Escape
Record summary
CVE-2019-25483 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.
Description
Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k contains a restricted shell escape vulnerability that allows local users to bypass command restrictions by using the command substitution operator $( ). Attackers can inject arbitrary commands through the $( ) syntax when passed as arguments to allowed commands like ping to execute unrestricted shell access.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AR-5310Browse Comtrend / AR-5310Default status: unaffected | CVE List | GE31-412SSG-C01_R10.A2pG039u.d24k | affected |
Proofs of concept
1Catalogued exploits
ExploitDBComtrend-AR-5310 - Restricted Shell EscapeExploitDB exploitby AMRI AmineNot analyzed1 file
References
4ExploitDB-47149exploit
https://www.exploit-db.com/exploits/47149 VulnCheck Advisory: Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k Restricted Shell EscapeThird-party advisory
https://www.vulncheck.com/advisories/comtrend-ar-5310-ge31-412ssg-c01-r10-a2pg039u-d24k-restricted-shell-escape vulncheck.com
https://www.vulncheck.com/advisories/comtrend-ar-ge-ssg-c-rapgudk-restricted-shell-escape