leoservalli/Privilege-escalation-MitraStar

leoservalli/Privilege-escalation-MitraStar

Releases0
Stars15
Privilege escalation vulnerability on MitraStar routers

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH9 HIGH

MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".