Vulnerabilities > Optilinknetwork > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-11-23 | CVE-2020-23584 | Command Injection vulnerability in Optilinknetwork Op-Xt71000N Firmware 3.3.1191028 Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution. | 9.8 |
2022-11-23 | CVE-2020-23591 | Unrestricted Upload of File with Dangerous Type vulnerability in Optilinknetwork Op-Xt71000N Firmware 3.3.1191028 A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse connection (using '.asp' webshell), backdoor. | 9.8 |
2022-11-23 | CVE-2020-23583 | Command Injection vulnerability in Optilinknetwork Op-Xt71000N Firmware 3.3.1191028 OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. | 9.8 |