An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
The vulnerability results from improper input validation in the mac2name function available through the web interface. An attacker can send a specially crafted HTTP request containing malicious data that is passed directly to the system shell without proper sanitization. The exploit requires authentication to the device's web interface, but once obtained, it is possible to execute arbitrary commands with the privileges of the process handling the interface.
An authenticated attacker can execute arbitrary system commands on the device, which may lead to complete device takeover, disclosure of sensitive data, modification of configuration, and system availability disruption.
Security patches available from the manufacturer should be applied according to the references — detailed information is available in the official Peplink security advisory at the address indicated in the manufacturer's references
Peplink Smart Reader firmware version 1.2.0
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HPeplink Smart Reader
HWPeplinkall versionsPeplink Smart Reader Firmware
OSPeplink1.2.0
Related vulnerabilities
A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink...
A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in...
An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of P...
An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality...
SQL Injection w urządzeniach Peplink Balance poprzez ciasteczko bauth