The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute arbitrary commands via shell metacharacters in the ping_ipaddr parameter. CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Publication date: Tue, 04 Feb 2014 11:39:00 +0000