7.2
CVSSv3

CVE-2017-12576

Published: 24/08/2018 Updated: 03/10/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

An issue exists on the PLANEX CS-QR20 1.30. A hidden and undocumented management page allows an malicious user to execute arbitrary code on the device when the user is authenticated. The management page was used for debugging purposes, once you login and access the page directly (/admin/system_command.asp), you can execute any command.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

planex cs-qr20_firmware 1.30

Exploits

PLANEX CS-QR20 suffers from a remote command execution vulnerability due to a hidden management page existing ...