CVE-2019-7383: Systrome Cumilon Isg-600c Firmware
High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.
An issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181105.bin. A shell command injection occurs by editing the description of an ISP file. The file network/isp/isp_update_edit.php does not properly validate user input, which leads to shell command injection via the des parameter.
Affected products
- Systrome Cumilon Isg-600c Firmware: version 1.1-r2.1 only
- Systrome Cumilon Isg-600h Firmware: version 1.1-r2.1 only
- Systrome Cumilon Isg-800w Firmware: version 1.1-r2.1 only
Published 2019-03-21. Last modified 2026-06-17.