Mingyu Security Gateway Remote Command Execution Vulnerability
Vulnerability
A remote command execution vulnerability has been identified in Mingyu Security Gateway versions prior to 3.0-5.3p. The issue arises in the 'webui/modules/log/fw_security.mds' file, where improper parameter handling allows for unauthorized command execution via the log_type parameter.
Impact
Exploitation of this vulnerability allows for remote command execution on the affected system.
Reproduction
To reproduce this vulnerability, send a request to the '/log/fw_security.mds' endpoint with a crafted log_type parameter that exploits the improper parameter handling. This will trigger the remote command execution on the server.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
