Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Shell command injection in 3onedata GW1101-1D(RS-485)-TB-P modbus gateway
Vulnerability Description
3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands in the context of the root user by providing payload in the "IP address" field of the diagnosis test tools. This issue has been resolved in firmware version 3.0.59B2024080600R4353
CVSS Information
N/A
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
3onedata GW1101-1D(RS-485)-TB-P 操作系统命令注入漏洞
Vulnerability Description
3onedata GW1101-1D(RS-485)-TB-P是中国3onedata公司的一款工业通信网关设备。 3onedata GW1101-1D(RS-485)-TB-P V2.2.0版本存在操作系统命令注入漏洞,该漏洞源于诊断测试工具的IP地址字段存在漏洞,允许经过身份验证的用户以root用户身份执行任意shell命令。
CVSS Information
N/A
Vulnerability Type
N/A