Headline
CVE-2020-23583: GitHub - huzaifahussain98/CVE-2020-23583: REMOTE CODE EXECUTION found in "OPTILINK OP-XT71000N".
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on “/diag_ping_admin.asp” to “PingTest” interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.
Name already in use
A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
1 branch 0 tags
Code
Use Git or checkout with SVN using the web URL.
Open with GitHub Desktop
Download ZIP
Latest commit
Files
Permalink
Failed to load latest commit information.
Type
Name
Latest commit message
Commit time
CVE-2020-23583
OPTILINK E-PON “MODEL NO: OP-XT71000N” with "HARDWARE VERSION: V2.2"; & “FIRMWARE VERSION: OP_V3.3.1-191028”
REMOTE CODE EXECUTION found in "OPTILINK OP-XT71000N". The issue occurs when the attacker sends an arbitrary code on “/diag_ping_admin.asp” to “PingTest” interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.
TARGET
/diag_ping_admin.asp
Attack Vector
pass arbitrary commands with IP-ADDRESS using " | " to execute commands.
REGARDS
Huzaifa Hussain
https://twitter.com/disguised_noob
https://www.linkedin.com/in/huzaifa-hussain-046791179