An issue was discovered in Victure RX1800 WiFi 6 Router ...
High severity
Unreviewed
Published
Dec 3, 2024
to the GitHub Advisory Database
•
Updated Dec 3, 2024
Description
Published by the National Vulnerability Database
Dec 2, 2024
Published to the GitHub Advisory Database
Dec 3, 2024
Last updated
Dec 3, 2024
An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /cgi-bin/luci/admin endpoints are vulnerable to command injection. Attackers can exploit this by sending crafted payloads through parameters intended for the ping utility, enabling arbitrary command execution with root-level permissions on the device.
References