Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://www.necplatforms.co.jp/product/security_ap/info_20201211.html | vendor advisory |
https://jvn.jp/en/jp/JVN55917325/index.html | third party advisory |
https://jvn.jp/jp/JVN55917325/index.html | third party advisory |