Vulnerability Description
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. The device has a command-injection vulnerability in the web management UI on NAS settings page "/cgi-bin/nasset.cgi". An attacker can send a crafted HTTP POST request to execute arbitrary code. Authentication is required before executing the attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Planex | Cs-W50Hd Firmware | < 030720 |
| Planex | Cs-W50Hd | - |
References
- http://seclists.org/fulldisclosure/2018/Aug/29Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2018/Aug/29Mailing ListThird Party Advisory
FAQ
What is CVE-2017-12573?
CVE-2017-12573 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. The device has a command-injection vulnerability in the web management UI on NAS settings page "/cgi-bin/nasset.cgi". An...
How severe is CVE-2017-12573?
CVE-2017-12573 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-12573?
Check the references section above for vendor advisories and patch information. Affected products include: Planex Cs-W50Hd Firmware, Planex Cs-W50Hd.