RSS   Vulnerabilities for 'Cumilon isg-800w firmware'   RSS

2019-03-21
 
CVE-2019-7383

CWE-77
 

 
An issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181105.bin. A shell command injection occurs by editing the description of an ISP file. The file network/isp/isp_update_edit.php does not properly validate user input, which leads to shell command injection via the des parameter.

 
 
CVE-2018-19525

CWE-352
 

 
An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add and /ui/?g=obj_keywords_addsave with resultant XSS because of a lack of csrf token validation.

 

 >>> Vendor: Systrome 6 Products
Isg-600c firmware
Isg-600h firmware
Isg-800w firmware
Cumilon isg-600c firmware
Cumilon isg-600h firmware
Cumilon isg-800w firmware


Copyright 2024, cxsecurity.com

 

Back to Top