OS Command Injection in AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Router - CVE-2019-5071
Published: November 22, 2019
AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Router
Detailed vulnerability description
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the "dns1" POST parameter in the "/goform/WanParameterSetting" resource. A local user attacker can send a specially crafted HTTP POST request and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.