VulnerabilityModified
CVE-2014-8387
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.
HIGH 9.0EPSS 30.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.
- CVSS 2.0
- 9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 30.95% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- advantech/eki-6340 firmware · advantech/eki-6340
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2014/Nov/58Exploit
- http://www.coresecurity.com/advisories/advantech-eki-6340-command-injectionExploit
- http://www.securityfocus.com/archive/1/534021/100/0/threaded
- http://www.securityfocus.com/bid/71192Exploit
- http://seclists.org/fulldisclosure/2014/Nov/58Exploit
- http://www.coresecurity.com/advisories/advantech-eki-6340-command-injectionExploit
- http://www.securityfocus.com/archive/1/534021/100/0/threaded
- http://www.securityfocus.com/bid/71192Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.