9.8
CVSSv3

CVE-2019-12489

Published: 26/11/2019 Updated: 24/08/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP request, it is possible to inject and execute a command between two & characters in the mount parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fastweb askey_rtv1907vw_firmware 0.00.81

Github Repositories

CVE-2019-12489

TLDR This is a brief report of a vulnerability (CVE-2019-12489) discovered playing around with a Fastgate modem/router of Fastweb and Ghidra The vulnerability allow the execution of a command injection through an http request and can be used to enable an SSH shell Firmware collection and extraction All the firmware files are located in 590121191:8080/ACS-server/file