CVE-2017-16934: OS Command Injection
The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a changepassword.csp request, which supports a "<%%25call system.exec:" string in the passwd parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16934?
CVE-2017-16934 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2017-16934?
To fix CVE-2017-16934, update your DBLTek web server to the latest version that contains the security patch.
What are the potential impacts of CVE-2017-16934?
CVE-2017-16934 allows remote attackers to execute arbitrary OS commands, leading to full system compromise.
Is CVE-2017-16934 exploitable remotely?
Yes, CVE-2017-16934 is exploitable remotely as it involves accessing the web server through a crafted request.
What devices are affected by CVE-2017-16934?
CVE-2017-16934 specifically affects DBLTek devices running the vulnerable version of the web server.