packetstormsecurity.com
http://packetstormsecurity.com/files/158888/Geutebruck-testaction.cgi-Remote-Command-Execution.html CVE-2020-16205
HIGH
Geutebruck testaction.cgi Remote Command Execution
Record summary
CVE-2020-16205 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit.
Description
Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2 and 1.12.14.5).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
G-Cam and G-Code | CVE List | Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2 and 1.12.14.5 | affected |
Proofs of concept
1Catalogued exploits
MetasploitGeutebruck testaction.cgi Remote Command ExecutionMetasploit exploitby Davy DouhineNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-16205 us-cert.cisa.gov
https://us-cert.cisa.gov/ics/advisories/icsa-20-219-03