RULE(RULE ID:338787)

Rule General Information
Release Date: 2025-04-08
Rule Name: Wangkang NS-ASG API index.php Remote Command Execution Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Netcom's NS-ASG application security gateway is a software and hardware integration product that integrates SSL and IPSec to ensure service access security, adapt to all mobile terminals, provide multiple link balancing and selection technologies, and support flexible combination of multiple authentication modes. And up to 13 authentication methods such as built-in SMS authentication, LDAP token, and USB KEY. The Nethealth NS-ASG security gateway index.php file has a remote command execution vulnerability. Attackers can obtain server permissions by constructing special request packets.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.