CVE-2017-12576: Critical severity PLANEX Cs-qr20 Firmware vulnerability
An issue was discovered on the PLANEX CS-QR20 1.30. A hidden and undocumented management page allows an attacker to execute arbitrary code on the device when the user is authenticated. The management page was used for debugging purposes, once you login and access the page directly (/admin/systemcommand.asp), you can execute any command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12576?
CVE-2017-12576 has a high severity rating due to its potential for arbitrary code execution on the device.
How do I fix CVE-2017-12576?
To mitigate CVE-2017-12576, update the firmware of your PLANEX CS-QR20 to the latest version provided by the manufacturer.
What devices are affected by CVE-2017-12576?
CVE-2017-12576 affects the PLANEX CS-QR20 with firmware version 1.30.
Can CVE-2017-12576 be exploited without authentication?
Exploitation of CVE-2017-12576 requires the attacker to be authenticated on the device.
What type of vulnerability is CVE-2017-12576?
CVE-2017-12576 is categorized as a remote code execution vulnerability.