Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the adjacent network to execute an arbitrary OS command via a specially crafted config file.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://business.ntt-east.co.jp/topics/2022/03_22.html | vendor advisory |
https://www.ntt-west.co.jp/smb/kiki_info/info/220322.html | vendor advisory |
https://jvn.jp/en/vu/JVNVU94900322/index.html | vdb entry third party advisory |