CVE-2020-7594
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metacharacters in the interface JSON field of the ping function.
Affected (1)
Products: Multitech: Conduit Mtcdt Lvw2 246a Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.17-ocea-13592 |
| Running on/with | Platform Versions |
|---|---|
Multitech Conduit Mtcdt Lvw2 246a | All versions |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.