Authentication Vulnerability in Riello NetMan 204 and 15-2
CVE-2017-6900
What is CVE-2017-6900?
An authentication vulnerability exists in Riello NetMan 204 versions 14-2 and 15-2 due to improper handling of variables in the login script and the wrongpass Python script. The failure to enclose variables $VAL0 and $VAL1 in quotes can lead to Bash command injection, while poor error handling allows an attacker to log in as an administrator by exploiting a specific username input. This vulnerability can be further exacerbated by the fact that login.cgi accepts the username as a GET parameter, enabling remote login via crafted URIs. The potential consequences include enabling telnet/SSH services and resetting local user credentials, which pose significant security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
