VYPR

DBLTek devices

by DBL

CVEs (1)

  • CVE-2017-16934CriNov 24, 2017
    risk 0.68cvss 9.8epss 0.13

    The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a change_password.csp…