← Back to CVEs
CVE-2020-17456
CRITICAL9.8
Description
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published8/20/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
seowonintech:slc-130seowonintech:slc-130_firmwareseowonintech:slr-120d42gseowonintech:slr-120d42g_firmwareseowonintech:slr-120sseowonintech:slr-120s42gseowonintech:slr-120s42g_firmwareseowonintech:slr-120s_firmwareseowonintech:slr-120t42gseowonintech:slr-120t42g_firmware
Weaknesses (CWE)
CWE-78
References
http://packetstormsecurity.com/files/158933/Seowon-SlC-130-Router-Remote-Code-Execution.html(cve@mitre.org)
http://packetstormsecurity.com/files/166273/Seowon-SLR-120-Router-Remote-Code-Execution.html(cve@mitre.org)
https://github.com/TAPESH-TEAM/CVE-2020-17456-Seowon-SLR-120S42G-RCE-Exploit-Unauthenticated(cve@mitre.org)
https://www.exploit-db.com/exploits/50821(cve@mitre.org)
http://packetstormsecurity.com/files/158933/Seowon-SlC-130-Router-Remote-Code-Execution.html(af854a3a-2127-422b-91ae-364da2661108)
http://packetstormsecurity.com/files/166273/Seowon-SLR-120-Router-Remote-Code-Execution.html(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/TAPESH-TEAM/CVE-2020-17456-Seowon-SLR-120S42G-RCE-Exploit-Unauthenticated(af854a3a-2127-422b-91ae-364da2661108)
https://maj0rmil4d.github.io/Seowon-SlC-130-And-SLR-120S-Exploit/(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/50821(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.