iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://www.ikuai8.com/component/download | product |
https://www.ikuai8.com/download.php?n=/3.x/iso/iKuai8_x64_3.6.7_Build202208301257.iso | vendor advisory |
https://github.com/yikesoftware/exp_and_poc_archive/tree/main/CVE/CVE-2022-40469 | third party advisory exploit |