Vulnerability Description
MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metacharacters in the interface JSON field of the ping function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Multitech | Conduit Mtcdt-Lvw2-246A Firmware | 1.4.17-ocea-13592 |
| Multitech | Conduit Mtcdt-Lvw2-246A | - |
Related Weaknesses (CWE)
References
- https://sku11army.blogspot.com/2020/01/multitech-authenticated-remote-code.htmlExploitThird Party Advisory
- https://sku11army.blogspot.com/2020/01/multitech-authenticated-remote-code.htmlExploitThird Party Advisory
FAQ
What is CVE-2020-7594?
CVE-2020-7594 is a vulnerability with a CVSS score of 7.2 (HIGH). MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metach...
How severe is CVE-2020-7594?
CVE-2020-7594 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7594?
Check the references section above for vendor advisories and patch information. Affected products include: Multitech Conduit Mtcdt-Lvw2-246A Firmware, Multitech Conduit Mtcdt-Lvw2-246A.