​A command injection vulnerability... CVE-2023-4212

- AV AC AU C I A
发布: 2023-08-22
修订: 2023-11-07

​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

0%
暂无可用Exp或PoC
当前有8条受影响产品信息