Loading vulnerability details…
CVSS v3.1
N/A
EPSS
3.48%
Published
Feb 20, 2018
Modified
Nov 21, 2024
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with XSS.
Weaknesses (CWE)
Affected Products (1)
References (6)