← Retour aux CVEs
CVE-2020-17456
CRITICAL9.8
Description
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.
Details CVE
Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie8/20/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
seowonintech:slc-130seowonintech:slc-130_firmwareseowonintech:slr-120d42gseowonintech:slr-120d42g_firmwareseowonintech:slr-120sseowonintech:slr-120s42gseowonintech:slr-120s42g_firmwareseowonintech:slr-120s_firmwareseowonintech:slr-120t42gseowonintech:slr-120t42g_firmware
Faiblesses (CWE)
CWE-78
References
http://packetstormsecurity.com/files/158933/Seowon-SlC-130-Router-Remote-Code-Execution.html(cve@mitre.org)
http://packetstormsecurity.com/files/166273/Seowon-SLR-120-Router-Remote-Code-Execution.html(cve@mitre.org)
https://github.com/TAPESH-TEAM/CVE-2020-17456-Seowon-SLR-120S42G-RCE-Exploit-Unauthenticated(cve@mitre.org)
https://www.exploit-db.com/exploits/50821(cve@mitre.org)
http://packetstormsecurity.com/files/158933/Seowon-SlC-130-Router-Remote-Code-Execution.html(af854a3a-2127-422b-91ae-364da2661108)
http://packetstormsecurity.com/files/166273/Seowon-SLR-120-Router-Remote-Code-Execution.html(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/TAPESH-TEAM/CVE-2020-17456-Seowon-SLR-120S42G-RCE-Exploit-Unauthenticated(af854a3a-2127-422b-91ae-364da2661108)
https://maj0rmil4d.github.io/Seowon-SlC-130-And-SLR-120S-Exploit/(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/50821(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.