CVE-2016-10098
UnknownEPSS 2.50%
Last modified
CVE-2016-10098 is a vulnerability of currently unknown severity. An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands.. EPSS estimates a 2.50% chance of exploitation in the next 30 days.
Description
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sendquick | Entera Sms Gateway Firmware | All versions |
| Sendquick | Avera Sms Gateway Firmware | All versions |
References
- https://niantech.io/blog/2017/02/05/vulns-multiple-vulns-in-sendquick-entera-avera-sms-gateway-appliances/Press/Media Coverage, Third Party Advisory, URL Repurposed
- https://niantech.io/blog/2017/02/05/vulns-multiple-vulns-in-sendquick-entera-avera-sms-gateway-appliances/Press/Media Coverage, Third Party Advisory, URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10098?
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands.
How severe is CVE-2016-10098?
Severity scoring for CVE-2016-10098 is pending analysis. The EPSS model estimates a 2.50% probability of exploitation in the next 30 days.
How do I fix CVE-2016-10098?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-10092Heap-based buffer overflow in the readContigStripsIntoBuffer…
- CVE-2016-10093Integer overflow in tools/tiffcp.c in LibTIFF 4.0.7, 3.9.3, …
- CVE-2016-10094Off-by-one error in the t2p_readwrite_pdf_image_tile functio…
- CVE-2016-10095Stack-based buffer overflow in the _TIFFVGetField function i…
- CVE-2016-10096SQL injection vulnerability in register.php in GeniXCMS befo…
- CVE-2016-10097XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlia…
- CVE-2016-10099Borg (aka BorgBackup) before 1.0.9 has a flaw in the cryptog…
- CVE-2016-1010Integer overflow in Adobe Flash Player before 18.0.0.333 and…8.8
- CVE-2016-10100Borg (aka BorgBackup) before 1.0.9 has a flaw in the way dup…
- CVE-2016-10101Information Disclosure can occur in Hitek Software's Automiz…
- CVE-2016-10102hitek.jar in Hitek Software's Automize uses weak encryption …
- CVE-2016-10103Information Disclosure can occur in encryptionProfiles.jsd i…
Are you affected by CVE-2016-10098?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
