cyberdanube.com
https://cyberdanube.com/en/en-multiple-vulnerabilities-in-korenix-jetwave-series CVE-2023-23295
HIGH
korenix jetwave_2212g_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2023-23295 has a selected CVSS score of 8.8 (high).
Description
Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 9, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 12, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
jetwave_2212g_firmwareBrowse korenix / jetwave_2212g_firmware | VulnCheck | Version data not supplied | |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-23295