Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-12272

EPSS 37.65% · P97
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-12272

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
OpenWrt LuCI 命令操作系统命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenWrt LuCI是一款用于OpenWrt(Linux发行版)的图形化配置界面。 OpenWrt LuCI 0.10及之前版本中的admin/status/realtime/bandwidth_status和admin/status/realtime/wireless_status端点存在命令操作系统命令注入漏洞。该漏洞源于外部输入数据构造可执行命令过程中,网络系统或产品未正确过滤其中的特殊元素。攻击者可利用该漏洞执行非法命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2019-12272

#POC DescriptionSource LinkShenlong Link
1Exp of cve-2019-12272https://github.com/HACHp1/LuCI_RCE_expPOC Details
2Version-contains-cve-2019-12272https://github.com/roguedream/lede-17.01.3POC Details
3Version-contains-cve-2019-12272https://github.com/nevercodecorrect/lede-17.01.3POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-12272

登录查看更多情报信息。

Same Patch Batch · n/a · 2019-05-23 · 48 CVEs total

CVE-2017-17061Open-Xchange OX App Suite 跨站脚本漏洞
CVE-2017-5212Open-Xchange OX App Suite 访问控制错误漏洞
CVE-2019-12300Buildbot 授权问题漏洞
CVE-2019-9949多款Western Digital产品后置链接漏洞
CVE-2019-12297Motorola CX2和Motorola M2 格式化字符串错误漏洞
CVE-2019-11873wolfSSL 缓冲区错误漏洞
CVE-2019-12295Wireshark 代码注入漏洞
CVE-2019-12293Poppler 缓冲区错误漏洞
CVE-2019-12042多款Panda Security产品权限许可和访问控制问题漏洞
CVE-2017-5210Open-Xchange OX App Suite 信息泄露漏洞
CVE-2017-5211Open-Xchange OX App Suite 输入验证错误漏洞
CVE-2017-17060Open-Xchange OX App Suite 授权问题漏洞
CVE-2017-15652Artifex Software Ghostscript 信息泄露漏洞
CVE-2017-15030Open-Xchange OX App Suite 跨站脚本漏洞
CVE-2017-15029Open-Xchange OX App Suite 代码问题漏洞
CVE-2019-12301Percona Server 授权问题漏洞
CVE-2017-13668Open-Xchange OX App Suite 跨站脚本漏洞
CVE-2017-11740ZOHO ManageEngine Application Manager 输入验证错误漏洞
CVE-2017-11739ZOHO ManageEngine Application Manager 跨站脚本漏洞
CVE-2017-11738ZOHO ManageEngine Application Manager SQL注入漏洞

Showing top 20 of 48 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-12272

No comments yet


Leave a comment