A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Weintek Easyweb
cpe:2.3:a:weintek:easyweb:2.1.53:*:*:*:*:*:*:*
|
— | — |
|
Weintek Cmt-3072xh2_Firmware
cpe:2.3:o:weintek:cmt-3072xh2_firmware:20231011:*:*:*:*:*:*:*
|
— | — |
|
Weintek Cmt-3072xh2
cpe:2.3:h:weintek:cmt-3072xh2:-:*:*:*:*:*:*:*
|
— | — |