CVE-2018-15477

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
30/08/2018
Last modified:
09/11/2018

Description

myStrom WiFi Switch V1 devices before 2.66 did not sanitize a parameter received from the cloud that was used in an OS command. Malicious servers were able to run operating system commands on the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mystrom:wifi_switch_firmware:*:*:*:*:*:*:*:* 2.66 (excluding)
cpe:2.3:h:mystrom:wifi_switch:v1:*:*:*:*:*:*:*