CVE-2020-8946: OS Command Injection
Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/syslogclean.cgi log3gtype parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8946?
CVE-2020-8946 is a vulnerability found in Netis WF2471 v1.2.30142 devices that allows an authenticated attacker to execute arbitrary OS commands.
How severe is CVE-2020-8946?
CVE-2020-8946 has a severity rating of 8.8, which is considered critical.
How does CVE-2020-8946 work?
CVE-2020-8946 works by allowing an attacker with authentication to execute arbitrary OS commands by exploiting shell metacharacters in the /cgi-bin-igd/sys_log_clean.cgi log_3g_type parameter.
What software versions are affected by CVE-2020-8946?
Netis WF2471 v1.2.30142 devices are affected by CVE-2020-8946.
Is Netis WF2471 v1.2.30142 vulnerable to CVE-2020-8946?
Yes, Netis WF2471 v1.2.30142 is vulnerable to CVE-2020-8946.
How can I fix CVE-2020-8946?
To fix CVE-2020-8946, it is recommended to update Netis WF2471 firmware to a version that addresses the vulnerability.