Dismissed
Permalink
CVE-2026-2686
9.8 CRITICAL
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Exploit Code Maturity (E): Proof-of-Concept (P)
- Remediation Level (RL): Workaround (W)
- Report Confidence (RC): Reasonable (R)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
2 packages
- tests.fetchFirefoxAddon.simple
- tests.fetchFirefoxAddon.overridden-source
- @LeSuisse dismissed
SECCN Dingcheng G10 session_login.cgi qq os command injection
A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file /cgi-bin/session_login.cgi. The manipulation of the argument User leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
References
-
VDB-346488 | SECCN Dingcheng G10 session_login.cgi qq os command injection technical-descriptionvdb-entry
-
-
Submit #754200 | SECCN SECCN G10 VPN V3.1.0.181203 Unauthorized RCE third-party-advisory
Affected products
G10
- ==3.1.0.181203
Ignored packages (2)
pkgs.tests.fetchFirefoxAddon.simple
None
-
nixos-unstable yvakg10w6mqw
- nixpkgs-unstable yvakg10w6mqw
- nixos-unstable-small yvakg10w6mqw
-
nixos-unstable yvakg10w6mqw
- nixpkgs-unstable yvakg10w6mqw
- nixos-unstable-small yvakg10w6mqw