CVE-2018-13320: OS Command Injection
System Command Injection in network.setauthsettings in Buffalo TS5600D1206 version 3.70-0.10 allows attackers to execute system commands via the adminUsername and adminPassword parameters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-13320?
CVE-2018-13320 is a system command injection vulnerability in network.set_auth_settings in Buffalo TS5600D1206 firmware version 3.70-0.10.
How does CVE-2018-13320 allow attackers to execute system commands?
CVE-2018-13320 allows attackers to execute system commands by exploiting the adminUsername and adminPassword parameters.
What is the severity of CVE-2018-13320?
CVE-2018-13320 has a severity score of 7.2, making it a high severity vulnerability.
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-13320?
CVE-2018-13320 is associated with CWE-77 (Improper Neutralization of Special Elements used in a Command) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command).
Where can I find more information about CVE-2018-13320?
You can find more information about CVE-2018-13320 at the following link: [https://blog.securityevaluators.com/buffalo-terastation-ts5600d1206-nas-cve-disclosure-ab5d159f036d](https://blog.securityevaluators.com/buffalo-terastation-ts5600d1206-nas-cve-disclosure-ab5d159f036d)