802
VMScore

CVE-2018-16752

Published: 20/09/2018 Updated: 03/10/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 802
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of admin for the admin account may be used in some cases.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linknet-usa lw-n605r_firmware 12.20.2.1486

Exploits

LW-N605R devices allow remote code execution via shell metacharacters in the HOST field of the ping feature at adm/systoolsasp Authentication is needed but the default password of admin for the admin account may be used in some cases ...