Silicon Labs
cpe:2.3:a:silabs:zigbee_emberznet:*:*:*:*:*:*:*
A vulnerability exists in certain Silicon Labs endpoints that accept user-controlled input through URLs in JSON format, allowing for command execution. The executed commands can open executables, but cannot include parameters or arguments. This vulnerability requires the attacker to be on the same network.
Exploitation of this vulnerability allows for unauthorized command execution, with the potential to open executables on the affected system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.