Quantum Networks Router Command Injection Vulnerability Allowing Remote Code Execution
Vulnerability
A command injection vulnerability has been identified in the Quantum Networks Router QN-I-470, specifically in firmware version 6.1.1.B1. This vulnerability arises from insufficient sanitization of user input in the management CLI interface. An authenticated remote attacker could exploit this issue by injecting arbitrary operating system commands, which could then be executed with root privileges on the affected device.
Impact
Exploitation of this vulnerability could lead to remote code execution with root privileges on the affected router.
Remediation
Users are advised to upgrade the Quantum Networks Router QN-I-470 to the latest firmware version 7.5.4.B9.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
