CVE-2019-25483
Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k Restricted Shell Escape
CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th
Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k contains a restricted shell escape vulnerability that allows local users to bypass command restrictions by using the command substitution operator $( ). Attackers can inject arbitrary commands through the $( ) syntax when passed as arguments to allowed commands like ping to execute unrestricted shell access.
| CWE | CWE-306 |
| Vendor | comtrend |
| Product | ar-5310 |
| Published | Mar 11, 2026 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for comtrend ar-5310
Be the first to know when new high vulnerabilities affecting comtrend ar-5310 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Comtrend / AR-5310
GE31-412SSG-C01_R10.A2pG039u.d24k
References
Credits
AMRI Amine