iWT FaceSentry
cpe:2.3:h:iwt:facesentry_access_control_system:*:*:*:*:*:*:*, +1 more
- 6.4.8 build 264 (Algorithm A16)
- 5.7.2 build 568 (Algorithm A14)
- 5.7.0 build 539 (Algorithm A14)
A command injection vulnerability has been identified in the FaceSentry Access Control System version 6.4.8. This vulnerability allows authenticated users to inject and execute arbitrary shell commands with root privileges. The issue arises in the 'pingTest.php' and 'tcpPortTest.php' scripts, where unsanitized input parameters can be exploited. The vulnerability is present in several different builds of the FaceSentry firmware.
Exploitation of this vulnerability allows for authenticated users to execute arbitrary commands as the root user, potentially leading to unauthorized system access or control.
The vulnerability can be reproduced by sending a POST request to 'pingTest.php' or 'tcpPortTest.php' with crafted 'strInIP' and 'strInPort' parameters. The default session cookie must be included in the request. The injected commands will be executed with root privileges, and the results can be retrieved from the web server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.