go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Cellopoint CelloOS - Remote Command Execution (RCE)

TVN ID TVN-202006002
CVE ID CVE-2020-17384
CVSS 7.2 (High)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products CelloOS v4.1.10 Build 20190922
Description Cellopoint Cellos v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system administrator, attackers can inject and remotely execute arbitrary command to manipulate the system.
Solution Update to v4.1.10 Build 20200210 or higher.
Credit Cyku Hong from DEVCORE (https://devco.re)
Public Date 2020-08-27
Top