CVE-2018-1143: OS Command Injection
Published Apr 19, 2018
·Updated
A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to twonkycommand.cgi.
Affected Software
2 affected components
Belkin N750 Firmware=1.10.22
Belkin N750
Event History
Apr 19, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-1143.
2
What is the severity of CVE-2018-1143?
The severity of CVE-2018-1143 is critical with a score of 9.8.
3
How can a remote unauthenticated user exploit CVE-2018-1143?
A remote unauthenticated user can exploit CVE-2018-1143 by sending a crafted HTTP request to twonky_command.cgi in the Belkin N750 router.
4
What software versions are affected by CVE-2018-1143?
The Belkin N750 firmware version 1.10.22 is affected by CVE-2018-1143.
5
Is the Belkin N750 router itself vulnerable to CVE-2018-1143?
No, the Belkin N750 router itself is not vulnerable to CVE-2018-1143.