CVE-2020-21992
Summary
| CVE | CVE-2020-21992 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-29 15:15:00 UTC |
| Updated | 2021-05-12 15:06:00 UTC |
| Description | Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. The issue exist due to the 'par' POST parameter not being sanitized when called with the 'testemail' module through web.cgi binary. The vulnerable CGI binary (ELF 32-bit LSB executable, ARM) is calling the 'sh' executable via the system() function to issue a command using the mailx service and its vulnerable string format parameter allowing for OS command injection with root privileges. An attacker can remotely execute system commands as the root user using default credentials and bypass access controls in place. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Inim | Smartliving 10100l | - | All | All | All |
| Hardware | Inim | Smartliving 10100lg3 | - | All | All | All |
| Operating System | Inim | Smartliving 10100lg3 Firmware | All | All | All | All |
| Operating System | Inim | Smartliving 10100lg3 Firmware | All | All | All | All |
| Operating System | Inim | Smartliving 10100l Firmware | All | All | All | All |
| Operating System | Inim | Smartliving 10100l Firmware | All | All | All | All |
| Hardware | Inim | Smartliving 1050 | - | All | All | All |
| Hardware | Inim | Smartliving 1050g3 | - | All | All | All |
| Operating System | Inim | Smartliving 1050g3 Firmware | All | All | All | All |
| Operating System | Inim | Smartliving 1050g3 Firmware | All | All | All | All |
| Operating System | Inim | Smartliving 1050 Firmware | All | All | All | All |
| Operating System | Inim | Smartliving 1050 Firmware | All | All | All | All |
| Hardware | Inim | Smartliving 505 | - | All | All | All |
| Operating System | Inim | Smartliving 505 Firmware | All | All | All | All |
| Operating System | Inim | Smartliving 505 Firmware | All | All | All | All |
| Hardware | Inim | Smartliving 515 | - | All | All | All |
| Operating System | Inim | Smartliving 515 Firmware | All | All | All | All |
| Operating System | Inim | Smartliving 515 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zero Science Lab » Inim Electronics SmartLiving SmartLAN/G/SI <=6.x Root Remote Command Execution | MISC | www.zeroscience.mk | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.