First published: Thu Oct 06 2022(Updated: )
Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh (e.g., command execution can occur via a reverse shell installed by install.sh).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Generex Cs141 Firmware | <=2.10 | |
Generex CS141 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-42457.
CVE-2022-42457 has a severity rating of 7.2 (Critical).
CVE-2022-42457 allows remote command execution through a web interface that reaches the 'run_update' function in /usr/bin/gxserve-update.sh.
Generex CS141 firmware versions up to and including 2.10 are affected by CVE-2022-42457.
No, the Generex CS141 device itself is not vulnerable to CVE-2022-42457.
To fix CVE-2022-42457, it is recommended to update to a patched version of Generex CS141 firmware.