First published: Mon Nov 26 2018(Updated: )
System Command Injection in network.set_auth_settings in Buffalo TS5600D1206 version 3.70-0.10 allows attackers to execute system commands via the adminUsername and adminPassword parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Buffalo TS5600D1206 Firmware | =3.61-0.10 | |
Buffalo TS5600D1206 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13320 is a system command injection vulnerability in network.set_auth_settings in Buffalo TS5600D1206 firmware version 3.70-0.10.
CVE-2018-13320 allows attackers to execute system commands by exploiting the adminUsername and adminPassword parameters.
CVE-2018-13320 has a severity score of 7.2, making it a high severity vulnerability.
CVE-2018-13320 is associated with CWE-77 (Improper Neutralization of Special Elements used in a Command) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command).
You can find more information about CVE-2018-13320 at the following link: [https://blog.securityevaluators.com/buffalo-terastation-ts5600d1206-nas-cve-disclosure-ab5d159f036d](https://blog.securityevaluators.com/buffalo-terastation-ts5600d1206-nas-cve-disclosure-ab5d159f036d)