CVE-2017-12576
Published on: 08/24/2018 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:26:30 PM UTC
Certain versions of Cs-qr20 from Planex contain the following vulnerability:
An issue was discovered on the PLANEX CS-QR20 1.30. A hidden and undocumented management page allows an attacker to execute arbitrary code on the device when the user is authenticated. The management page was used for debugging purposes, once you login and access the page directly (/admin/system_command.asp), you can execute any command.
- CVE-2017-12576 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.2 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 9 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Full Disclosure: CVE-2017-12576: an hidden management page in PLANEX CS-QR20 | Mailing List Third Party Advisory seclists.org text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Planex | Cs-qr20 | - | All | All | All |
Hardware
| Planex | Cs-qr20 | - | All | All | All |
Operating System | Planex | Cs-qr20 Firmware | 1.30 | All | All | All |
Operating System | Planex | Cs-qr20 Firmware | 1.30 | All | All | All |
- cpe:2.3:h:planex:cs-qr20:-:*:*:*:*:*:*:*:
- cpe:2.3:h:planex:cs-qr20:-:*:*:*:*:*:*:*:
- cpe:2.3:o:planex:cs-qr20_firmware:1.30:*:*:*:*:*:*:*:
- cpe:2.3:o:planex:cs-qr20_firmware:1.30:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE