Command Injection in the Ping Module in the Web Interface on Technicolor TD5336 OI_Fw_v7 devices allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the pingAddr parameter to mnt_ping.cgi.
References
Link Resource
http://jordyf.me/2017/09/02/technicolor-pwn.html Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-09-04T20:00:00

Updated: 2017-09-04T19:57:01

Reserved: 2017-09-04T00:00:00


Link: CVE-2017-14127

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-09-04T20:29:00.290

Modified: 2017-09-08T20:33:58.627


Link: CVE-2017-14127

JSON object: View

cve-icon Redhat Information

No data.

CWE