CVE-2018-18879

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
18/06/2019
Last modified:
18/06/2019

Description

In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:columbiaweather:weather_microserver_firmware:ms_2.6.9900:*:*:*:*:*:*:*
cpe:2.3:h:columbiaweather:weather_microserver:-:*:*:*:*:*:*:*