CVE-2020-12124
wavlink wn530h4_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2020-12124 has a selected CVSS score of 9.8 (critical); EIP currently links 2 repository PoCs and 1 Nuclei template.
Description
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wn530h4_firmwareBrowse wavlink / wn530h4_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
2Repository PoCs
GitHubdb44k/CVE-2020-12124Repository PoCby db44kStars: 0Not analyzed3 files
GitHubScorpion-Security-Labs/CVE-2020-12124Repository PoCby Scorpion-Security-LabsStars: 0Not analyzed16 files
Nuclei templates
1ProjectDiscoveryCRITICALWAVLINK WN530H4 live_api.cgi - Command InjectionCVSS 9.8
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.
Impact
Unauthenticated attackers can execute arbitrary Linux commands as root on the WAVLINK WN530H4 device, potentially leading to complete system compromise, data theft, or using the device as a pivot point for further attacks.
Remediation
Apply vendor security patches if available or replace the device with a secure alternative. Restrict access to the management interface.
Source: ProjectDiscovery