CVE Published: 20/11/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: krcert |
Vendor: Netis Korea |
Product: D\'live set-top box AP(WF2429TB) Status : PUBLISHED
CVE-2020-7842 Description
Improper Input validation vulnerability exists in Netis Korea D\'live AP which could cause arbitrary command injection and execution when the time setting (using ntpServerlp1 parameter) for the users. This affects D\'live set-top box AP(WF2429TB) v1.1.10.
Metrics
CVSS Version: 3.1 |
Base Score: 6.4 MEDIUM Vector: CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
l➤ Exploitability Metrics: Attack Vector (AV)* ADJACENT_NETWORK Attack Complexity (AC)* HIGH Privileges Required (PR)* HIGH User Interaction (UI)* NONE Scope (S)* UNCHANGED
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* HIGH