Description
Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
1.04.1.592.* (custom) before 1.04.1.592.8
1.04.1.613.* (custom) before 1.04.1.613.13
1.04.1.* (custom) before 1.04.1.675
1.04.1.592.* (custom) before 1.04.1.592.8
1.04.1.613.* (custom) before 1.04.1.613.13
1.04.1.* (custom) before 1.04.1.675
1.04.1.592.* (custom) before 1.04.1.592.8
1.04.1.613.* (custom) before 1.04.1.613.13
1.04.1.* (custom) before 1.04.1.675
1.04.1.592.* (custom) before 1.04.1.592.8
1.04.1.613.* (custom) before 1.04.1.613.13
1.04.1.* (custom) before 1.04.1.675
References
www.twcert.org.tw/tw/cp-132-8279-bf67e-1.html
www.twcert.org.tw/en/cp-139-8280-ae6e1-2.html