CVE-2019-10660: OS Command Injection
Grandstream GXV3611IRHD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10660?
CVE-2019-10660 is a vulnerability in Grandstream GXV3611IR_HD devices that allows remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field.
How can remote authenticated users exploit CVE-2019-10660?
Remote authenticated users can exploit CVE-2019-10660 by using shell metacharacters in the /goform/systemlog?cmd=set logserver field to execute arbitrary code.
What is the severity of CVE-2019-10660?
CVE-2019-10660 has a severity rating of 8.8 (high).
What is the affected software for CVE-2019-10660?
The affected software for CVE-2019-10660 is Grandstream GXV3611IR_HD firmware versions up to and excluding 1.0.3.23.
Is Grandstream GXV3611IR_HD vulnerable to CVE-2019-10660?
No, Grandstream GXV3611IR_HD devices are not vulnerable to CVE-2019-10660.