Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config_valid.xgi?exeshell%60telnetd%20%26%60 URI.
Publication date: Tue, 13 Apr 2021 11:15:00 +0000