CurryRaid/iot_vul

CurryRaid/iot_vul

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.