T&W.BE126.Webupg.Command.Injection
Description
This indicates an attack attempt to exploit a Code Injection vulnerability in the T&W BE126 devices.
The vulnerability is due to insufficient sanitizing of user-supplied inputs in the application. A remote, unauthenticated attacker can exploit of this via a crafted request to a vulnerable device. Successful exploitation can lead to OS command execution on the server.
Affected Products
T&W BE126
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Currently we are unaware of any vendor supplied patch or updates available for this issue.
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |
Version Updates
| Date | Version | Status | Detail |
|---|---|---|---|
| 2024-10-08 | 28.877 |
Modified
|
Default_action:pass:drop |