First published: Sat Mar 30 2019(Updated: )
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grandstream Gwn7610 Firmware | <1.0.8.18 | |
Grandstream GWN7610 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10658 is a vulnerability in Grandstream GWN7610 devices that allows remote authenticated users to execute arbitrary code.
CVE-2019-10658 has a severity rating of 8.8 (high).
Grandstream GWN7610 devices before version 1.0.8.18 are affected by CVE-2019-10658.
An attacker can exploit CVE-2019-10658 by using shell metacharacters in the filename in a specific API call.
No, only versions before 1.0.8.18 of Grandstream GWN7610 are vulnerable to CVE-2019-10658.