mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
18 lines
825 B
Markdown
18 lines
825 B
Markdown
### [CVE-2021-44080](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44080)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://research.nccgroup.com/2022/05/24/technical-advisory-sercomm-h500s-authenticated-remote-command-execution-cve-2021-44080/
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|