CVE-2019-7385
An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 or below, The values of the newpass and confpass parameters in /bin/WebMGR are used in a system call in the firmware. Because there is no user input validation, this leads to authenticated code execution on the device.
Published:Mar 17, 2019
Last Modified:Nov 21, 2024
EPS:Mar 17, 2019
EPSS Score:0.05234
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Raisecom
Product
Iscom Ht803g-1ge
Raisecom
Iscom Ht803g-1ge
Vendor
Raisecom
Product
Iscom Ht803g-1ge Firmware
Raisecom
Iscom Ht803g-1ge Firmware
Vendor
Raisecom
Product
Iscom Ht803g-u
Raisecom
Iscom Ht803g-u
Vendor
Raisecom
Product
Iscom Ht803g-u Firmware
Raisecom
Iscom Ht803g-u Firmware
Vendor
Raisecom
Product
Iscom Ht803g-w
Raisecom
Iscom Ht803g-w
Vendor
Raisecom
Product
Iscom Ht803g-w Firmware
Raisecom
Iscom Ht803g-w Firmware
Vendor
Raisecom
Product
Iscom Ht803g Gpon
Raisecom
Iscom Ht803g Gpon
Vendor
Raisecom
Product
Iscom Ht803g Gpon Firmware
Raisecom
Iscom Ht803g Gpon Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
