First published: Sat Mar 30 2019(Updated: )
Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.apply update_nds_webroot_from_tmp API call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grandstream GWN7000 firmware | <1.0.6.32 | |
Grandstream GWN7000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10656 is a vulnerability that allows remote authenticated users to execute arbitrary code on Grandstream GWN7000 devices.
CVE-2019-10656 has a severity rating of 8.8 on the CVSS scale, indicating it is a critical vulnerability.
Grandstream GWN7000 devices with firmware up to and including version 1.0.6.32 are affected by CVE-2019-10656.
Remote authenticated users can exploit CVE-2019-10656 by using shell metacharacters in the filename in a specific API call.
To fix CVE-2019-10656, update the Grandstream GWN7000 firmware to version 1.0.6.33 or later.