Command Injection Vulnerability in Barco TransForm N Solution
CVE-2020-17503
7.2HIGH
What is CVE-2020-17503?
The NDN-210 device from Barco's TransForm N solution has a web administration panel that is accessible over HTTPS. A command injection vulnerability exists due to improper handling of the 'locking' parameter in split_card_cmd.php. This issue allows authenticated users of the administration panel to execute arbitrary commands remotely, potentially compromising the server's security. Users are encouraged to upgrade to TransForm N version 3.8 or later to mitigate this risk.