An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Se descubrió un problema en Lantronix EDS5000 2.1.0.0R3. El módulo HTTP RPC ejecuta un comando de shell para escribir registros cuando la autenticación del usuario falla. El nombre de usuario se concatena directamente con el comando sin ninguna sanitización. Esto permite a los atacantes inyectar comandos arbitrarios del sistema operativo en el parámetro de nombre de usuario. Los comandos inyectados se ejecutan con privilegios de root.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Attack Requirements | NONE |
| Privileges Required | NONE |
| User Interaction | NONE |
| Vulnerability Confidentiality | HIGH |
| Vulnerability Integrity | HIGH |
| Vulnerability Availability | HIGH |
| Subsequent Confidentiality | NONE |
| Subsequent Integrity | NONE |
| Subsequent Availability | NONE |
Source: [email protected]
Type: Secondary
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-78
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| lantronix | eds5008_firmware | * | <built-in method update of dict object at 0x7fd2a1f394c0> | Operating System |
| lantronix | eds5016_firmware | * | <built-in method update of dict object at 0x7fd2a1f3ad80> | Operating System |
| lantronix | eds5032_firmware | * | <built-in method update of dict object at 0x7fd31b2a7240> | Operating System |
| lantronix | g526gp12s_firmware | * | <built-in method update of dict object at 0x7fd319997f80> | Operating System |
| lantronix | g526gp17s_firmware | * | <built-in method update of dict object at 0x7fd2a1f39f00> | Operating System |
| lantronix | g526gp1cs_firmware | * | <built-in method update of dict object at 0x7fd2a1f39200> | Operating System |
| lantronix | g526gp1asg_firmware | * | <built-in method update of dict object at 0x7fd3423b1dc0> | Operating System |
| lantronix | g526gp1as_firmware | * | <built-in method update of dict object at 0x7fd386740b40> | Operating System |
| lantronix | g527gp22s_firmware | * | <built-in method update of dict object at 0x7fd340a1db40> | Operating System |
| lantronix | g527gp27s_firmware | * | <built-in method update of dict object at 0x7fd2a1f3a0c0> | Operating System |
| lantronix | g527gp2as_firmware | * | <built-in method update of dict object at 0x7fd2a1b43c80> | Operating System |
| lantronix | g527gp2asg_firmware | * | <built-in method update of dict object at 0x7fd384e09640> | Operating System |
| lantronix | g528gp2fs_firmware | * | <built-in method update of dict object at 0x7fd2a1b42840> | Operating System |
| lantronix | g528gp2fsg_firmware | * | <built-in method update of dict object at 0x7fd369e20080> | Operating System |
| lantronix | g528gp2fsgc_firmware | * | <built-in method update of dict object at 0x7fd36b1e7900> | Operating System |
| lantronix | x300f202s_firmware | * | <built-in method update of dict object at 0x7fd36bda0dc0> | Operating System |
| lantronix | x303f202s_firmware | * | <built-in method update of dict object at 0x7fd2a1f38740> | Operating System |
| lantronix | x304g00as_firmware | * | <built-in method update of dict object at 0x7fd36b404200> | Operating System |
| lantronix | x304g000s_firmware | * | <built-in method update of dict object at 0x7fd36b1e4040> | Operating System |
| lantronix | x304g002s_firmware | * | <built-in method update of dict object at 0x7fd3408d1b40> | Operating System |
| lantronix | x304g007s_firmware | * | <built-in method update of dict object at 0x7fd2dbe44c80> | Operating System |
| lantronix | x304g00cs_firmware | * | <built-in method update of dict object at 0x7fd384e08680> | Operating System |
| lantronix | e228g002s_firmware | * | <built-in method update of dict object at 0x7fd2a1f3bdc0> | Operating System |
| lantronix | e228g004s_firmware | * | <built-in method update of dict object at 0x7fd2dbe44540> | Operating System |
| lantronix | e228g00cb28_firmware | * | <built-in method update of dict object at 0x7fd36b9120c0> | Operating System |
| lantronix | e228g00cs_firmware | * | <built-in method update of dict object at 0x7fd360277680> | Operating System |
| lantronix | e213f102s_firmware | * | <built-in method update of dict object at 0x7fd36b407ec0> | Operating System |
| lantronix | e214f002s_firmware | * | <built-in method update of dict object at 0x7fd36b404b00> | Operating System |
| lantronix | e214f00cs_firmware | * | <built-in method update of dict object at 0x7fd369ec58c0> | Operating System |
| lantronix | e214g000s_firmware | * | <built-in method update of dict object at 0x7fd36b1e6200> | Operating System |
| lantronix | e214g001s_firmware | * | <built-in method update of dict object at 0x7fd3423b3f80> | Operating System |
| lantronix | e218f004s_firmware | * | <built-in method update of dict object at 0x7fd369ec7440> | Operating System |
| lantronix | e218g107s_firmware | * | <built-in method update of dict object at 0x7fd3423b21c0> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:eds5008_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:eds5008:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:eds5016_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:eds5016:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:eds5032_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:eds5032:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:g526gp12s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:g526gp12s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:g526gp17s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:g526gp17s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:g526gp1cs_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:g526gp1cs:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:g526gp1asg_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:g526gp1asg:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:g526gp1as_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:g526gp1as:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:g527gp22s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:g527gp22s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:g527gp27s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:g527gp27s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:g527gp2as_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:g527gp2as:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:g527gp2asg_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:g527gp2asg:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:g528gp2fs_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:g528gp2fs:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:g528gp2fsg_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:g528gp2fsg:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:g528gp2fsgc_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:g528gp2fsgc:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:x300f202s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:x300f202s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:x303f202s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:x303f202s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:x304g00as_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:x304g00as:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:x304g000s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:x304g000s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:x304g002s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:x304g002s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:x304g007s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:x304g007s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:x304g00cs_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:x304g00cs:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:e228g002s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:e228g002s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:e228g004s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:e228g004s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:e228g00cb28_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:e228g00cb28:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:e228g00cs_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:e228g00cs:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:e213f102s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:e213f102s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:e214f002s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:e214f002s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:e214f00cs_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:e214f00cs:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:e214g000s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:e214g000s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:e214g001s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:e214g001s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:e218f004s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:e218f004s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:e218g107s_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:e218g107s:-:*:*:*:*:*:*:* |