CVE-2013-7179

Published Feb 4, 2014

Last updated 9 years ago

Overview

Description
The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute arbitrary commands via shell metacharacters in the ping_ipaddr parameter.
Source
cret@cert.org
NVD status
Analyzed

Risk scores

CVSS 2.0

Type
Primary
Base score
8.3
Impact score
10
Exploitability score
6.5
Vector string
AV:A/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-20

Social media

Hype score
Not currently trending

Evaluator

Comment
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Impact
-
Solution
-

Configurations