VYPR
Unrated severityNVD Advisory· Published Oct 11, 2019· Updated Aug 5, 2024

CVE-2019-17499

CVE-2019-17499

Description

The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly validate ping command arguments, which allows remote authenticated users to execute OS commands as root via shell metacharacters in the Target_IP parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated users can execute OS commands as root via shell metacharacters in the ping Target_IP parameter on Compal CH7465LG devices, firmware 6.12.18.25-2p4.

Vulnerability

The setter.xml component of the Common Gateway Interface on Compal CH7465LG cable modem/router devices running firmware version 6.12.18.25-2p4 does not properly sanitize the Target_IP argument passed to the ping command. This allows injection of shell metacharacters, leading to OS command injection as root. The vulnerability resides in the administrative web interface, requiring authenticated access to the CGI endpoint.

Exploitation

An attacker must have valid administrative credentials to access the device's web interface. By crafting a Target_IP parameter that includes shell metacharacters (e.g., ;, |, ` ``), the attacker can append arbitrary OS commands after the ping destination. The device then executes the entire string as a root shell command.

Impact

Successful exploitation grants the attacker remote code execution with root privileges on the device. This enables full compromise of the router/modem, including ability to modify network settings, intercept traffic, install persistent malware, or pivot to other devices on the local network.

Mitigation

As of the publication date (2019-10-11), no official firmware update or patch has been released by Compal. Affected users should restrict administrative access to trusted IPs only, disable remote management if possible, and monitor for vendor updates. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.

[1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Compal/CH7465LGdescription
  • Compal/CH7465LGllm-create
    Range: =6.12.18.25-2p4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.