?A command injection vulnerability exists in Trane XL824...
Moderate severity
Unreviewed
Published
Aug 22, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Aug 22, 2023
Published to the GitHub Advisory Database
Aug 22, 2023
Last updated
Apr 4, 2024
?A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.
References