Multiple command injection vulnerabilities exist in the...
Critical severity
Unreviewed
Published
Jul 1, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jun 30, 2022
Published to the GitHub Advisory Database
Jul 1, 2022
Last updated
Jan 27, 2023
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.The
/ajax/remove_sniffer_raw_log/
API is affected by a command injection vulnerability.References