File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget function in the /sbin/cloudadmin.sh component.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/Push3AX/vul/blob/main/DCN/DCFW_1800_SDC_CommandInjection.md | third party advisory exploit |
https://www.dcnetworks.com.cn/goods/61.html | product |