Critical
Low
Medium
CVE-2016-15047
Overview
AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke ...
Critical
Low
Medium
No items found.