China Mobile An Lianbao WF-1 V1.0.1 router provides a web...
High severity
Unreviewed
Published
Jan 19, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Jan 18, 2022
Published to the GitHub Advisory Database
Jan 19, 2022
Last updated
Feb 3, 2023
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.
References