CVE-2019-12272: OS Command Injection
Published May 23, 2019
·Updated
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidthstatus and admin/status/realtime/wirelessstatus of the web application are affected by a command injection vulnerability.
Affected Software
1 affected component
OpenWrt LuCI<=0.10.0
Remediation
Patch Available
Event History
May 23, 2019
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-12272.
2
What is the severity rating of CVE-2019-12272?
CVE-2019-12272 has a severity rating of 9.8 (critical).
3
Which software versions are affected by CVE-2019-12272?
OpenWrt LuCI versions up to and including 0.10.0 are affected by CVE-2019-12272.
4
What is the CWE ID for this vulnerability?
The CWE IDs for CVE-2019-12272 are 77 and 78.
5
How can I fix CVE-2019-12272?
To fix CVE-2019-12272, you should update OpenWrt LuCI to a version beyond 0.10.0.