Vulnerability Description
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alleghenycreative | Openrepeater | < 2.2 |
Related Weaknesses (CWE)
References
- https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2019-25024.md
- https://github.com/OpenRepeater/openrepeater/issues/66ExploitThird Party Advisory
- https://github.com/codexlynx/CVE-2019-25024Third Party Advisory
- https://github.com/OpenRepeater/openrepeater/issues/66ExploitThird Party Advisory
- https://github.com/codexlynx/CVE-2019-25024Third Party Advisory
FAQ
What is CVE-2019-25024?
CVE-2019-25024 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.
How severe is CVE-2019-25024?
CVE-2019-25024 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-25024?
Check the references section above for vendor advisories and patch information. Affected products include: Alleghenycreative Openrepeater.