Loading
System command injection in User.create method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute system commands via the "name" parameter.
Use CWE-78, Buffalo vendor hub and Ts5600d1206 Firmware product page to widen CVE-2018-13318 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-13324, CVE-2018-13321 and CVE-2018-13319 for nearby disclosures in the same product family.