CVE-2022-42457
CVE-2022-42457
Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh (e.g., command execution can occur via a reverse shell installed by install.sh).
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:H/S:C/UI:N
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://github.com/hubertfarnsworth12/Generex-CS141-Authenticated-Remote-Command-Executionhttps://github.dev/hubertfarnsworth12/Generex-CS141-Authenticated-Remote-Command-Executionhttps://www.generex.de/products/ups/https://www.generex.de/support/downloads/ups/cs141https://www.generex.de/support/downloads/ups/cs141/update