CVE-2019-16398

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
19/09/2019
Last modified:
21/07/2021

Description

On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file named zskj_script_run.sh that executes a reverse shell.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:keeper:k5_firmware:20.1.0.25:*:*:*:*:*:*:*
cpe:2.3:o:keeper:k5_firmware:20.1.0.63:*:*:*:*:*:*:*
cpe:2.3:h:keeper:k5:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools