an issue was discovered on WAVLINK AERIAL X 1200M devices where a crafted POST request can be sent to adm.cgi that will result in the execution of the supplied command if there is an active session at the same time
WAVLINK AERIAL X 1200M
In adm.cgi, the received POST is directly spliced to the system function for execution
PeiWen.Huang
Yuyu.Cao
Shengjie.Xu