CVE-2023-26802
dcnglobal dcbi-netlog-lab_firmware Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2023-26802 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 1, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dcbi-netlog-lab_firmwareBrowse dcnglobal / dcbi-netlog-lab_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALDCBI-Netlog-LAB v1.0 - Command InjectionCVSS 9.8
An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request.
Impact
Unauthenticated attackers can bypass authentication and execute arbitrary OS commands on the DCN DCBI-Netlog-LAB device, leading to complete device compromise and potential network infiltration.
Remediation
Upgrade to the latest firmware version from DCN that addresses this command injection vulnerability, or apply vendor-provided security patches.
Source: ProjectDiscovery