The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operating System.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://www.stengg.com/cybersecurity | vendor advisory |
https://www.stengg.com/media/1076253/vpncrypt-m10-cve-advisory-notice.pdf | vendor advisory |