Skip to content

Instantly share code, notes, and snippets.

@somerandomdudeonetheinternet
somerandomdudeonetheinternet / Galleon Systems GPS Command Injection.txt
Created May 6, 2022 21:48
An issue was discovered in Galleon NTS-6002-GPS > 4.14.103-Galleon-NTS-6002 V12-4
> An authenticated attacker can perform
> command injection as root via shell metacharacters within the Network
> Tools section of the web-management interface. All three networking
> tools are affected (Ping, Traceroute, and DNS Lookup) and their
> respective input fields (ping_address, trace_address,
> nslookup_address).
>
> ------------------------------------------
>
> [VulnerabilityType Other]