9.8
CVSSv3

CVE-2017-16934

Published: 24/11/2017 Updated: 11/12/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The web server on DBL DBLTek devices allows remote malicious users to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a change_password.csp request, which supports a "<%%25call system.exec:" string in the passwd parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dbltek web server -

Exploits

## Vulnerabilities summary The following advisory describes 2 (two) vulnerabilities found in DblTek webserver DBL is “specialized in VoIP products, especially GoIPs We design, develop, manufacture, and sell our products directly and via distributors to customers Our GoIP models now cover 1, 4, 8, 16, and 32-channel in order to meet the wide r ...