### [CVE-2018-20162](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20162) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root. ### POC #### Reference - http://packetstormsecurity.com/files/151719/Digi-TransPort-LR54-Restricted-Shell-Escape.html - http://packetstormsecurity.com/files/151719/Digi-TransPort-LR54-Restricted-Shell-Escape.html - https://blog.hackeriet.no/cve-2018-20162-digi-lr54-restricted-shell-escape/ - https://blog.hackeriet.no/cve-2018-20162-digi-lr54-restricted-shell-escape/ - https://seclists.org/bugtraq/2019/Feb/34 - https://seclists.org/bugtraq/2019/Feb/34 #### Github - https://github.com/0xT11/CVE-POC - https://github.com/stigtsp/CVE-2018-20162-digi-lr54-restricted-shell-escape