nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-10173 CVE-2020-10173
HIGH
comtrend vr-3033_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2020-10173 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 7, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
vr-3033_firmwareBrowse comtrend / vr-3033_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBComtrend VR-3033 - Command InjectionExploitDB exploitby Raki Ben HamoudaNot analyzed1 file
References
2exploit-db.com
https://www.exploit-db.com/exploits/48142