First published: Sat Mar 30 2019(Updated: )
Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grandstream Gxv3611ir Hd Firmware | <1.0.3.23 | |
Grandstream Gxv3611ir Hd |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10660 is a vulnerability in Grandstream GXV3611IR_HD devices that allows remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field.
Remote authenticated users can exploit CVE-2019-10660 by using shell metacharacters in the /goform/systemlog?cmd=set logserver field to execute arbitrary code.
CVE-2019-10660 has a severity rating of 8.8 (high).
The affected software for CVE-2019-10660 is Grandstream GXV3611IR_HD firmware versions up to and excluding 1.0.3.23.
No, Grandstream GXV3611IR_HD devices are not vulnerable to CVE-2019-10660.