ABUS.TVIP20000-21150.wireless_mft.Command.Injection
Description
This indicates an attack attempt to exploit a Command Injection Vulnerability in ABUS TVIP 20000-21150.
The vulnerability is due to the shell metacharacters in the /cgi-bin/mft/wireless_mft ap field. A remote, unauthenticated attacker can exploit this vulnerability by sending crafted requests to the vulnerable server. Successful exploitation could result in arbitrary code execution with valid privileges.
Affected Products
ABUS TVIP 20000-21150
Impact
System Compromise: Remote attackers can execute arbitrary script code within the context of the target user's browser
Recommended Actions
Currently we are unaware of any vendor supplied patch for this issue.
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |