CVE-2018-15481

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
21/08/2018
Last modified:
03/10/2019

Description

Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices using firmware version 5.1.x before 5.1.13 allows authenticated remote attackers to escape the shell and escalate their privileges by adding a LocalCommand to the SSH configuration file in the user home folder.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ucopia:wireless_appliance_firmware:*:*:*:*:*:*:*:* 5.1.0 (including) 5.1.13 (including)
cpe:2.3:h:ucopia:wireless_appliance:-:*:*:*:*:*:*:*