CVE-2020-7594

HIGH

MultiTech Conduit MTCDT-LVW2-24XX 1.4.17 OS Command Injection via Debug Ping

Title source: llm
STIX 2.1

Description

MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metacharacters in the interface JSON field of the ping function.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0249
EPSS Percentile 82.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
multitech/conduit_mtcdt-lvw2-246a_firmware 1.4.17-ocea-13592
Published Jan 21, 2020
Tracked Since Feb 18, 2026