gist.github.com
https://gist.github.com/yinfei6/3664387cb5b66b68c7eff4bfdb51b2d6 CVE-2023-24796
CRITICAL
Vinga WR-AC1200 Password Parameter Vulnerability
Record summary
CVE-2023-24796 has a selected CVSS score of 9.8 (critical).
Description
Password vulnerability found in Vinga WR-AC1200 81.102.1.4370 and before allows a remote attacker to execute arbitrary code via the password parameter at the /goform/sysTools and /adm/systools.asp endpoints.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 11, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 3, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wr-ac1200_firmwareBrowse vinga / wr-ac1200_firmware | VulnCheck | Version data not supplied | |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-24796