Files
CVEs-PoC/2020/CVE-2020-10173.md
T
2024-06-18 02:51:15 +02:00

18 lines
722 B
Markdown

### [CVE-2020-10173](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10173)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.
### POC
#### Reference
- https://www.exploit-db.com/exploits/48142
#### Github
- https://github.com/ARPSyndicate/cvemon