Home / os / bsd

LW-N605R Remote Code Execution

Posted on 11 September 2018

LW-N605R devices allow remote code execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of admin for the admin account may be used in some cases.

 

TOP