ID

VAR-201608-0490


TITLE

NETRUN VPN Internet Behavior Management Router Arbitrary File Read and Remote Command Execution Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-05900

DESCRIPTION

NetRun is currently the domestic network terminal equipment and application provider. NetRun products cover Internet access, secure VPN (virtual private network), online behavior management, community broadband access, professional traffic control, and billing management system. The NETRUNVPN Internet Behavior Management Router has arbitrary file read and remote command execution vulnerabilities under certain conditions. Remote attackers exploit vulnerabilities to obtain sensitive file information such as password files and remotely execute system commands.

Trust: 0.6

sources: CNVD: CNVD-2016-05900

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-05900

AFFECTED PRODUCTS

vendor:net runmodel:vpn internet behavior management routerscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-05900

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-05900
value: HIGH

Trust: 0.6

CNVD: CNVD-2016-05900
severity: HIGH
baseScore: 8.5
vectorString: AV:N/AC:M/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.8
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-05900

EXTERNAL IDS

db:WOOYUNid:WOOYUN-2016-0221474

Trust: 0.6

db:CNVDid:CNVD-2016-05900

Trust: 0.6

sources: CNVD: CNVD-2016-05900

REFERENCES

url:http://www.wooyun.org/bugs/wooyun-2016-0221474/

Trust: 0.6

sources: CNVD: CNVD-2016-05900

SOURCES

db:CNVDid:CNVD-2016-05900

LAST UPDATE DATE

2022-05-17T01:55:52.242000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-05900date:2016-08-03T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-05900date:2016-08-03T00:00:00