CVE-2017-20221: Telesquare SKT LTE Router SDT-CS3B1 CSRF System Command Execution
Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains a cross-site request forgery vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting missing request validation. Attackers can craft malicious web pages that perform administrative actions when visited by logged-in users, enabling command execution with router privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-20221?
CVE-2017-20221 has a moderate severity rating due to its potential for system command execution by authenticated attackers.
How do I fix CVE-2017-20221?
To fix CVE-2017-20221, apply the latest firmware update provided by Telesquare for the SKT LTE Router SDT-CS3B1.
What type of vulnerability is CVE-2017-20221?
CVE-2017-20221 is a cross-site request forgery (CSRF) vulnerability that allows execution of arbitrary system commands.
Who is affected by CVE-2017-20221?
Users of Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 are affected by CVE-2017-20221.
Can CVE-2017-20221 lead to complete system compromise?
Yes, an attacker exploiting CVE-2017-20221 can potentially execute arbitrary commands, leading to complete system compromise.