CVE-2019-7384: OS Command Injection
An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U2.0.0140521R4.1.47.002 or below. The value of the fmgponloid parameter is used in a system call inside the boa binary. Because there is no user input validation, this leads to authenticated code execution on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7384?
CVE-2019-7384 is classified as a high severity vulnerability due to the potential for authenticated shell command injection.
How do I fix CVE-2019-7384?
To fix CVE-2019-7384, update the firmware of affected Raisecom ISCOM HT803G products to a version above ISCOMHT803G-U_2.0.0_140521_R4.1.47.002.
Which products are affected by CVE-2019-7384?
CVE-2019-7384 affects the Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products running vulnerable firmware.
What kind of vulnerability is CVE-2019-7384?
CVE-2019-7384 is an authenticated shell command injection vulnerability that can be exploited through specific system calls.
Is CVE-2019-7384 remotely exploitable?
CVE-2019-7384 requires authenticated access to the devices, making it less likely to be exploited remotely without credentials.