The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1034553 | vdb entry |
https://www.kb.cert.org/vuls/id/BLUU-9ZQU2R | us government resource |
https://www.exploit-db.com/exploits/38455/ | exploit |
https://www.kb.cert.org/vuls/id/870744 | third party advisory us government resource |