CVE-2019-10658: OS Command Injection
Published Mar 30, 2019
·Updated
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.updatendswebrootfromtmp updatendswebrootfromtmp API call.
Affected Software
2 affected components
Grandstream Gwn7610 Firmware<1.0.8.18
Grandstream GWN7610
Event History
Mar 30, 2019
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
Description
Frequently Asked Questions
1
What is CVE-2019-10658?
CVE-2019-10658 is a vulnerability in Grandstream GWN7610 devices that allows remote authenticated users to execute arbitrary code.
2
How severe is CVE-2019-10658?
CVE-2019-10658 has a severity rating of 8.8 (high).
3
Which Grandstream GWN7610 devices are affected by CVE-2019-10658?
Grandstream GWN7610 devices before version 1.0.8.18 are affected by CVE-2019-10658.
4
How can an attacker exploit CVE-2019-10658?
An attacker can exploit CVE-2019-10658 by using shell metacharacters in the filename in a specific API call.
5
Are all versions of Grandstream GWN7610 vulnerable to CVE-2019-10658?
No, only versions before 1.0.8.18 of Grandstream GWN7610 are vulnerable to CVE-2019-10658.