Home
HIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NHIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 4.8.0 Build 20260316
affected
Description
The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and execute operating system commands outside the originally authorized scope.
Problem types
CWE-1284 Improper validation of specified quantity in input
Product status
Any version before 4.8.0 Build 20260316
References
www.twcert.org.tw/tw/cp-132-10966-3258e-1.html
www.twcert.org.tw/en/cp-139-10965-3ce75-2.html