First published: Fri Aug 24 2018(Updated: )
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. The device has a command-injection vulnerability in the web management UI on NAS settings page "/cgi-bin/nasset.cgi". An attacker can send a crafted HTTP POST request to execute arbitrary code. Authentication is required before executing the attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Planex Cs-w50hd Firmware | <030720 | |
PLANEX CS-W50HD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12573 has been classified as a high severity vulnerability due to its command-injection capability.
To mitigate CVE-2017-12573, upgrade the firmware of the PLANEX CS-W50HD device to a version newer than 030720.
CVE-2017-12573 affects PLANEX CS-W50HD devices with firmware versions prior to 030720.
Yes, an attacker can exploit CVE-2017-12573 by sending a crafted HTTP POST request to the device's web management UI.
Yes, exploiting CVE-2017-12573 requires authentication to access the web management UI of the device.