Record summary

CVE-2020-12124 has a selected CVSS score of 9.8 (critical); EIP currently links 2 repository PoCs and 1 Nuclei template.

Description

A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 30, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
2
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

2

Repository PoCs

GitHubdb44k/CVE-2020-12124Repository PoCby db44kStars: 0Not analyzed3 files

6.3 KiB

GitHub

PoC details
GitHubScorpion-Security-Labs/CVE-2020-12124Repository PoCby Scorpion-Security-LabsStars: 0Not analyzed16 files

1.1 MiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALWAVLINK WN530H4 live_api.cgi - Command InjectionCVSS 9.8

A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.

Impact

Unauthenticated attackers can execute arbitrary Linux commands as root on the WAVLINK WN530H4 device, potentially leading to complete system compromise, data theft, or using the device as a pivot point for further attacks.

Remediation

Apply vendor security patches if available or replace the device with a secure alternative. Restrict access to the management interface.

WeaknessesCWE-78
AuthorsDhiyaneshDK
Template tagscvecve2020rcewavlinkvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:wavlink:wn530h4_firmware:m30h4.v5030.190403:*:*:*:*:*:*:*
Shodan: http.html:"wavlink"
FOFA: body="wavlink"

Source: ProjectDiscovery

References

3