CVE-2024-29292

Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi parameters.
Configurations

No configuration.

History

27 Nov 2024, 17:15

Type Values Removed Values Added
CWE CWE-77
Summary
  • (es) Varias vulnerabilidades de inyección de comandos del sistema operativo que afectan al enrutador Kasda LinkSmart KW6512 &lt;= v1.3 permiten a un atacante remoto autenticado ejecutar comandos arbitrarios del sistema operativo a través de varios parámetros cgi.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

20 Nov 2024, 21:15

Type Values Removed Values Added
Summary (en) Multiple OS Command Injection vulnerabilities affecting Kasda KW6512 router software version KW6512_Linux_V1.0 enable an authenticated remote attacker to execute arbitrary OS commands via Quick Setup and Internet page parameters passed to internet.cgi. (en) Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi parameters.

20 Nov 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-20 18:15

Updated : 2024-11-27 17:15


NVD link : CVE-2024-29292

Mitre link : CVE-2024-29292

CVE.ORG link : CVE-2024-29292


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')