← Back

CVE-2020-21992

nvd nist
Published: Apr 29, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. The issue exist due to the 'par' POST parameter not being sanitized when called with the 'testemail' module through web.cgi binary. The vulnerable CGI binary (ELF 32-bit LSB executable, ARM) is calling the 'sh' executable via the system() function to issue a command using the mailx service and its vulnerable string format parameter allowing for OS command injection with root privileges. An attacker can remotely execute system commands as the root user using default credentials and bypass access controls in place.

Affected (6)

6 products
Smartliving 505 Firmware
Smartliving 515 Firmware
Smartliving 1050 Firmware
Smartliving 1050g3 Firmware
Smartliving 10100l Firmware
Smartliving 10100lg3 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 6.0
Running on/withPlatform Versions
Inim
Smartliving 505
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 6.0
Running on/withPlatform Versions
Inim
Smartliving 515
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 6.0
Running on/withPlatform Versions
Inim
Smartliving 1050
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 6.0
Running on/withPlatform Versions
Inim
Smartliving 1050g3
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 6.0
Running on/withPlatform Versions
Inim
Smartliving 10100l
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 6.0
Running on/withPlatform Versions
Inim
Smartliving 10100lg3
All versions

References (2)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.