Telesquare TLR-2005KSH
cpe:2.3:h:telesquare:tlr-2005ksh:*:*:*:*:*:*:*, +1 more
- 1.2.4
A command injection vulnerability has been identified in the Telesquare TLR-2005KSH router, specifically in version 1.2.4. The issue arises within the CGI file 'internet.cgi', when the 'Command' parameter is set to 'lanCfg'. The vulnerability allows remote attackers to manipulate the 'Hostname' argument, leading to unauthorized command execution on the device.
Exploitation of this vulnerability allows for arbitrary command execution on the affected router.
To reproduce this vulnerability, send a request to '/cgi-bin/internet.cgi' with the 'Command' parameter set to 'lanCfg' and the 'hostname' parameter injected with a command payload, such as '$(cmd)'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.