CVE-2017-18378

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
11/06/2019
Last modified:
09/10/2019

Description

In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=writeuploaddir remote command execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netgear:readynas_surveillance_firmware:*:*:*:*:*:*:arm:* 1.1.4-7 (excluding)
cpe:2.3:o:netgear:readynas_surveillance_firmware:*:*:*:*:*:*:x86:* 1.4.3-17 (excluding)
cpe:2.3:h:netgear:readynas_surveillance:-:*:*:*:*:*:*:*