Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `peerPin` request's parameter.
2024-07-08T16:15:07.093
2024-11-21T08:36:56.563
Modified
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | realtek | rtl819x_jungle_software_development_kit | 3.4.11 | Yes |
Operating System | level1 | wbr-6013_firmware | rer4_a_v3411b_2t2r_lev_09_170623 | Yes |
Hardware | level1 | wbr-6013 | - | No |