InfraPower PPS-02-S Q213V1...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary InfraPower Manager PPS-02-S is a FREE built-in GUI of each IP dongle ( IPD-02-S only ) to remotely monitor the connected PDUs. Patented IP Dongle provides IP remote access to the PDUs by a true network IP address chain. Only 1xIP dongle allows access to max. 16 PDUs in daisy chain - which is a highly efficient cient application for saving not only the IP remote accessories cost, but also the true IP addresses required on the PDU management. ### Description InfraPower suffers from multiple unauthenticated remote command injection vulnerabilities. The vulnerability exist due to several POST parameters in several scripts not being sanitized when using the exec(), proc_open(), popen() and shell_exec() PHP function while updating the settings on the affected device. This allows the attacker to execute arbitrary system commands as the root user and bypass access controls in place. ### Vendor Austin Hughes Electronics Ltd. - http://www.austin-hughes.com ### Affected Version *...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息