First published: Mon Jul 08 2019(Updated: )
Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by sed injection in cgi-bin/camctrl_save_profile.cgi (save parameter) and cgi-bin/ddns.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet Fcm-mb40 Firmware | =1.2.0.0 | |
Fortinet Fcm-mb40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.