RULE(RULE ID:333720)

Rule General Information
Release Date: 2021-07-01
Rule Name: China Telecom Configuration Management System SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: China Telecom is one of the largest state-owned telecommunications companies in China, providing a comprehensive range of fixed line and mobile communications services, Internet access services, data communications services, multimedia communications services and other related services worldwide. SQL injection vulnerability exists in manager/login.php on the front landing page of China Telecom Gateway Configuration Management system. This vulnerability is caused by insufficient verification of input parameters, and an attacker can inject malicious SQL statements into the application to perform unauthorized operations.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Network Device
Reference:
Solutions
Please contact the software vendor to update the software patch.