CVE-2022-27946
https://notcve.org/view.php?id=CVE-2022-27946
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to admin_account.cgi. Los dispositivos NETGEAR R8500 versión 1.0.2.158, permiten a usuarios remotos autenticados ejecutar comandos arbitrarios (como telnetd) por medio de metacaracteres de shell en los parámetros sysNewPasswd y sysConfirmPasswd del archivo admin_account.cgi • https://github.com/donothingme/VUL/blob/main/vul3/3.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-27947
https://notcve.org/view.php?id=CVE-2022-27947
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameter. Los dispositivos NETGEAR R8500 versión 1.0.2.158, permiten a usuarios remotos autenticados ejecutar comandos arbitrarios (como telnetd) por medio de metacaracteres de shell en los parámetros ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length o ipv6_lan_length • https://github.com/donothingme/VUL/blob/main/vul1/1.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-27945
https://notcve.org/view.php?id=CVE-2022-27945
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to password.cgi. Los dispositivos NETGEAR R8500 versión 1.0.2.158, permiten a usuarios remotos autenticados ejecutar comandos arbitrarios (como telnetd) por medio de metacaracteres de shell en los parámetros sysNewPasswd y sysConfirmPasswd del archivo password.cgi • https://github.com/donothingme/VUL/blob/main/vul2/2.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •