An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.
References
Configurations
No configuration.
History
03 Apr 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.yuque.com/jichujiliangdanwei/vwbq9e/ux1426h170rhgfn7 - | |
Summary |
|
|
CWE | CWE-77 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
02 Apr 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-02 21:15
Updated : 2025-04-07 14:18
NVD link : CVE-2025-29063
Mitre link : CVE-2025-29063
CVE.ORG link : CVE-2025-29063
JSON object : View
Products Affected
No product.
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')