Remote Command Execution Vulnerability in Dynacolor FCM-MB40 Products
CVE-2019-13398
7.2HIGH
Summary
Dynacolor FCM-MB40 devices running version 1.2.0.0 are susceptible to a remote command execution vulnerability, allowing attackers to execute arbitrary commands through specially crafted parameters targeting specific CGI scripts. Key scripts affected include cgi-bin/camctrl_save_profile.cgi and cgi-bin/ddns.cgi, which can be manipulated via sed injection techniques. This vulnerability presents a significant risk, potentially compromising device integrity and security.
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved