An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of "plugin/controllers/models/config.py" performs an eval() call on the contents of the "key" HTTP GET parameter. This allows an unauthenticated remote attacker to execute arbitrary Python code or OS commands via api/saveconfig.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2017-06-22T03:00:00
Updated: 2024-08-05T17:18:01.914Z
Reserved: 2017-06-21T00:00:00
Link: CVE-2017-9807

No data.

Status : Deferred
Published: 2017-06-22T03:29:00.207
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-9807

No data.