CVE-2017-12573: Planex Cs-w50hd Firmware
High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. The device has a command-injection vulnerability in the web management UI on NAS settings page "/cgi-bin/nasset.cgi". An attacker can send a crafted HTTP POST request to execute arbitrary code. Authentication is required before executing the attack.
Affected products
- Planex Cs-w50hd Firmware: before 030720 (fixed in 030720)
Published 2018-08-24. Last modified 2026-06-17.