Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/ZRQos/set_online_client.
References
Link | Resource |
---|---|
http://iot.10086.cn/?l=en-us | Product |
https://github.com/pokerfacett/MY_REQUEST/blob/master/China%20Mobile%20An%20Lianbao%20WF-1%20router%20Command%20Injection.md | Third Party Advisory |
https://www.zhipinmall.com/prodetail?id=1266#skuId=3020 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-04-29T15:44:03
Updated: 2021-04-29T15:44:03
Reserved: 2021-01-22T00:00:00
Link: CVE-2021-25812
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-04-29T16:15:09.873
Modified: 2021-05-07T18:31:44.527
Link: CVE-2021-25812
JSON object: View
Redhat Information
No data.
CWE