Files
CVEs-PoC/2019/CVE-2019-10658.md
2025-09-29 21:09:30 +02:00

832 B

CVE-2019-10658

Description

Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call.

POC

Reference

Github