#VU29420 Command Injection in PA6 Wi-Fi Powerline extender - CVE-2019-16213

 

#VU29420 Command Injection in PA6 Wi-Fi Powerline extender - CVE-2019-16213

Published: June 30, 2020


Vulnerability identifier: #VU29420
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-16213
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
PA6 Wi-Fi Powerline extender
Software vendor:
Shenzhen Tenda Technology Co.,Ltd.

Description

The vulnerability allows a remote attacker to execute arbitrary commands on the system.

The vulnerability exists due to improper input validation. A remote authenticated attacker can send a specially crafted string, modify the device name of an attached PLC adapter and execute arbitrary commands on the target system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links