Vulnerability Description
On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Seowonintech | Swr-300A Firmware | - |
| Seowonintech | Swr-300A | - |
| Seowonintech | Swr-300B Firmware | - |
| Seowonintech | Swr-300B | - |
| Seowonintech | Swr-300C Firmware | - |
| Seowonintech | Swr-300C | - |
| Seowonintech | Swr-300Bg Firmware | - |
| Seowonintech | Swr-300Bg | - |
Related Weaknesses (CWE)
References
- https://ethical-hacker.org/en/seowonintech-remote-root/ExploitThird Party Advisory
- https://ethical-hacker.org/en/seowonintech-remote-root/ExploitThird Party Advisory
FAQ
What is CVE-2016-10760?
CVE-2016-10760 is a vulnerability with a CVSS score of 9.8 (CRITICAL). On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter.
How severe is CVE-2016-10760?
CVE-2016-10760 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-10760?
Check the references section above for vendor advisories and patch information. Affected products include: Seowonintech Swr-300A Firmware, Seowonintech Swr-300A, Seowonintech Swr-300B Firmware, Seowonintech Swr-300B, Seowonintech Swr-300C Firmware.