CVE-2017-12576
Last modified
CVE-2017-12576 is a vulnerability of currently unknown severity. An issue was discovered on the PLANEX CS-QR20 1.30. A hidden and undocumented management page allows an attacker to execute arbitrary code on the device when the user is authenticated. EPSS estimates a 2.20% chance of exploitation in the next 30 days.
Description
An issue was discovered on the PLANEX CS-QR20 1.30. A hidden and undocumented management page allows an attacker to execute arbitrary code on the device when the user is authenticated. The management page was used for debugging purposes, once you login and access the page directly (/admin/system_command.asp), you can execute any command.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Planex | Cs-Qr20 Firmware | 1.30 |
References
- http://seclists.org/fulldisclosure/2018/Aug/27Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2018/Aug/27Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12576?
How severe is CVE-2017-12576?
How do I fix CVE-2017-12576?
Are you affected by CVE-2017-12576?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
