OS Command Injection vulnerability in OKER G955V1 v1.03.02.20161128, allows physical attackers to interrupt the boot sequence and execute arbitrary commands with root privileges.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://www.okerthai.com | vendor advisory |
https://www.dropbox.com/s/cnzwbxhxl0ahzoa/OKER_UART_2.mp4 | third party advisory exploit |
https://gist.github.com/tanprathan/69fbf6fbac11988e12f44069ec5b18ea#file-cve-2020-22007-txt | third party advisory |