COMFAST CF-XR11 V2.7.2 has a command injection...
Critical severity
Unreviewed
Published
Aug 15, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Aug 15, 2023
Published to the GitHub Advisory Database
Aug 15, 2023
Last updated
Apr 4, 2024
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr.
References