An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary one with root privileges.
Se descubrió un problema en Lantronix EDS3000PS 3.1.0.0R2. El parámetro host del cliente TFTP en la página del navegador de archivos no se sanea correctamente. Esto puede explotarse para escapar del comando original y ejecutar uno arbitrario con privilegios de root.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Type: Secondary
Exploitability Score: 3.9
Impact Score: 5.9
| Source | Type | Description |
|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary |
en
CWE-78
en
CWE-288
en
CWE-620
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| lantronix | eds3016ps1ns_firmware | 3.1.0.0r2 | <built-in method update of dict object at 0x7763a06a13c0> | Operating System |
| lantronix | eds3008ps1ns_firmware | 3.1.0.0r2 | <built-in method update of dict object at 0x7763bb2c8180> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:eds3016ps1ns_firmware:3.1.0.0r2:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:eds3016ps1ns:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:lantronix:eds3008ps1ns_firmware:3.1.0.0r2:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:lantronix:eds3008ps1ns:-:*:*:*:*:*:*:* |