OS Command Injection in ViewPower - CVE-2023-51585
Published: December 22, 2023
ViewPower
Voltronic Power
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the USBCommEx shutdown method. A remote unauthenticated attacker can trick ab authenticated administrator to trigger a shutdown operation and execute arbitrary OS commands on the target system.