First published: Wed Feb 12 2020(Updated: )
Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/sys_log_clean.cgi log_3g_type parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netis-systems Wf2471 Firmware | =1.2.30142 | |
Netis-systems Wf2471 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8946 is a vulnerability found in Netis WF2471 v1.2.30142 devices that allows an authenticated attacker to execute arbitrary OS commands.
CVE-2020-8946 has a severity rating of 8.8, which is considered critical.
CVE-2020-8946 works by allowing an attacker with authentication to execute arbitrary OS commands by exploiting shell metacharacters in the /cgi-bin-igd/sys_log_clean.cgi log_3g_type parameter.
Netis WF2471 v1.2.30142 devices are affected by CVE-2020-8946.
Yes, Netis WF2471 v1.2.30142 is vulnerable to CVE-2020-8946.
To fix CVE-2020-8946, it is recommended to update Netis WF2471 firmware to a version that addresses the vulnerability.