CVE-2018-20122

The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary that is vulnerable to a command injection vulnerability that can be exploited to achieve remote code execution with root privileges. No authentication is required in order to trigger the vulnerability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:fastweb:fastgate_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fastweb:fastgate:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-02-21 14:29

Updated : 2023-12-10 12:44


NVD link : CVE-2018-20122

Mitre link : CVE-2018-20122

CVE.ORG link : CVE-2018-20122


JSON object : View

Products Affected

fastweb

  • fastgate_firmware
  • fastgate
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')