Description
wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite the default executable/binary path and its arguments. An attacker can abuse this functionality to execute arbitrary code.
Remediation
References
https://github.com/thingsSDK/wifiscanner/issues/1
Related Vulnerabilities
CVE-2018-3758 Vulnerability in npm package express-cart
CVE-2020-7737 Vulnerability in npm package safetydance
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk15on
CVE-2023-49376 Vulnerability in maven package com.jfinal:jfinal
CVE-2017-3201 Vulnerability in maven package com.exadel.flamingo.flex:amf-serializer