Loading
Generated remediation guidance and an executive summary. No account required.
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call.
Use CWE-78, Grandstream vendor hub and Gwn7610 Firmware product page to widen CVE-2019-10658 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-10657 for nearby disclosures in the same product family.