CVE-2017-16522: Critical severity mitrastar gpt-2541gnac-n1 firmware vulnerability
Published Nov 3, 2017
·Updated
MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES113WJY0b16 devices allow remote authenticated users to obtain root access by specifying /bin/sh as the command to execute.
Affected Software
4 affected components
MitraStar Gpt-2541gnac Firmware=1.00\(vnj0\)b1
MitraStar GPT-2541GNAC
MitraStar Dsl-100hn-t1 Firmware=es_113wjy0b16
MitraStar DSL-100HN-T1
Event History
Nov 3, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16522?
CVE-2017-16522 has a high severity rating due to the potential for remote authenticated users to obtain root access.
2
How do I fix CVE-2017-16522?
To fix CVE-2017-16522, update the firmware of the MitraStar GPT-2541GNAC or DSL-100HN-T1 devices to a version that addresses this vulnerability.
3
Who is affected by CVE-2017-16522?
CVE-2017-16522 affects users of MitraStar GPT-2541GNAC firmware version 1.00(VNJ0)b1 and DSL-100HN-T1 firmware version ES_113WJY0b16.
4
What can an attacker do with CVE-2017-16522?
An attacker exploiting CVE-2017-16522 can gain unauthorized root access to the affected devices.
5
When was CVE-2017-16522 discovered?
CVE-2017-16522 was disclosed on November 14, 2017.