Vulnerabilities (CVE)

Filtered by vendor Teracue Subscribe
Filtered by product Enc-400 Hdmi
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20218 1 Teracue 6 Enc-400 Hdmi, Enc-400 Hdmi2, Enc-400 Hdmi2 Firmware and 3 more 2019-10-03 10.0 HIGH 9.8 CRITICAL
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter in the login form.