CVE-2020-7594
Summary
| CVE | CVE-2020-7594 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-21 22:15:00 UTC |
| Updated | 2020-01-29 17:50:00 UTC |
| Description | MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metacharacters in the interface JSON field of the ping function. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Multitech | Conduit Mtcdt-lvw2-246a | - | All | All | All |
| Hardware | Multitech | Conduit Mtcdt-lvw2-246a | - | All | All | All |
| Operating System | Multitech | Conduit Mtcdt-lvw2-246a Firmware | 1.4.17-ocea-13592 | All | All | All |
| Operating System | Multitech | Conduit Mtcdt-lvw2-246a Firmware | 1.4.17-ocea-13592 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Blogger | MISC | sku11army.blogspot.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.