Authentication Vulnerability in Riello NetMan 204 and 15-2
CVE-2017-6900
9.8CRITICAL
What is CVE-2017-6900?
An authentication vulnerability exists in Riello NetMan 204 versions 14-2 and 15-2 due to improper handling of variables in the login script and the wrongpass Python script. The failure to enclose variables $VAL0 and $VAL1 in quotes can lead to Bash command injection, while poor error handling allows an attacker to log in as an administrator by exploiting a specific username input. This vulnerability can be further exacerbated by the fact that login.cgi accepts the username as a GET parameter, enabling remote login via crafted URIs. The potential consequences include enabling telnet/SSH services and resetting local user credentials, which pose significant security risks.
