Vulnerabilities
Vulnerable Software
Kratosdefense:  Security Vulnerabilities
A remotely exploitable command injection vulnerability was found on the Kratos NGC-IDU 9.1.0.4. An attacker can execute arbitrary Linux commands as root by sending crafted TCP requests to the device.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-07-18
Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) within the IDU by sending crafted TCP requests to the IDU.
CVSS Score
9.8
EPSS Score
0.002
Published
2023-07-18
A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband (NB) before 1.7.5. As an admin user, an attacker can send a crafted password in order to execute Linux commands as the root user.
CVSS Score
7.2
EPSS Score
0.003
Published
2023-06-12


Contact Us

Shodan ® - All rights reserved