SAPIDO RB-1732
cpe:2.3:h:sapido:rb-1732:*:*:*:*:*:*:*, +1 more
- 2.0.43
A remote command execution vulnerability exists in the SAPIDO RB-1732 router, specifically in version 2.0.43. This vulnerability allows unauthenticated attackers to execute arbitrary system commands by sending malicious input to the formSysCmd endpoint. Exploitation involves POST requests with the sysCmd parameter containing shell commands, which are executed on the device with router privileges.
Exploitation of this vulnerability allows for remote command execution on the affected device with router privileges.
To reproduce this vulnerability, send a POST request to the '/goform/formSysCmd' endpoint. Include the sysCmd parameter with the desired shell command. The command will be executed on the device, and the output can be retrieved from the response.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.