Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.
References
Link | Resource |
---|---|
https://jvn.jp/en/jp/JVN55917325/index.html | Third Party Advisory |
https://jvn.jp/jp/JVN55917325/index.html | Third Party Advisory |
https://www.necplatforms.co.jp/product/security_ap/info_20201211.html | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jpcert
Published: 2020-12-14T02:25:51
Updated: 2020-12-14T02:25:51
Reserved: 2020-01-06T00:00:00
Link: CVE-2020-5635
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-12-14T03:15:13.417
Modified: 2020-12-15T18:01:35.677
Link: CVE-2020-5635
JSON object: View
Redhat Information
No data.
CWE