CVE-2014-8387 Information

Description

cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.

Reference

http://seclists.org/fulldisclosure/2014/Nov/58 http://www.coresecurity.com/advisories/advantech-eki-6340-command-injection http://www.securityfocus.com/archive/1/534021/100/0/threaded http://www.securityfocus.com/bid/71192

Share on: