Geutebruck testaction.cgi Remote Command Execution

Discussion in 'News Aggregator' started by Packet Storm, 18 Feb 2017.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a an arbitrary command execution vulnerability. The vulnerability exists in the /uapi-cgi/viewer/testaction.cgi page and allows an anonymous user to execute arbitrary commands with root privileges. Firmware EFD-2250 running 1.11.0.12 firmware.

    Continue reading...
     

Share This Page

Loading...