Vulnerabilities > Comtrend > VR 3033 Firmware > de11.416ssg.c01.r02.a2pvi042j1.d26m

DATE CVE VULNERABILITY TITLE RISK
2020-03-05 CVE-2020-10173 OS Command Injection vulnerability in Comtrend Vr-3033 Firmware De11416Ssgc01R02.A2Pvi042J1.D26M
Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.
network
low complexity
comtrend CWE-78
critical
9.0