I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94594 | vdb entry third party advisory vendor advisory |
http://www.iodata.jp/support/information/2016/ts-wrlap_2/ | vendor advisory |
https://jvn.jp/en/jp/JVN25059363/index.html | vdb entry third party advisory |