漏洞描述 Cisco Unified Industrial Wireless Software是美国思科(Cisco)公司的专为工业环境设计的无线软件,它支持高可用性、低延迟和零数据包丢失,适用于移动机器和其他资产的无线连接。 Cisco Unified Industrial Wireless Software存在命令注入漏洞,该漏洞源于对基于Web的管理界面的输入验证不当。未经身份验证的远程攻击者以root权限对底层操作系统执行命令注入攻击。
相关漏洞推荐 POC CVE-2024-0799: Arcserve Unified Data Protection - Authentication Bypass POC CVE-2024-0801: Arcserve Unified Data Protection - Unauthenticated DoS in ASNative.dll SourceCodester Pet Grooming Management Software SQL注入漏洞 SourceCodester Pet Grooming Management Software SQL注入漏洞 SourceCodester Pet Grooming Management Software SQL注入漏洞 Securden Unified PAM 认证绕过漏洞(CVE-2025-53118) White Star Software Protop /pt3upd/ 目录遍历漏洞 (CVE-2025-44177) Cisco Secure Firewall Management Center和Cisco Secure Firewall Threat Defense 操作系统命令注入漏洞 POC CVE-2001-0537: Cisco IOS HTTP Configuration - Authentication Bypass POC CVE-2009-1558: Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion POC CVE-2011-3315: Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal POC CVE-2013-5528: Cisco Unified Communications Manager 7/8/9 - Directory Traversal POC CVE-2015-0554: ADB/Pirelli ADSL2/2+ Wireless Router P.DGA4001N - Information Disclosure