CVE-2023-33381

HIGH

MitraStar GPT-2741GNAC - Command Injection

Title source: llm
STIX 2.1

Description

A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0b7_2). The vulnerability allows an authenticated user to execute arbitrary OS commands by sending specially crafted input to the router via the ping function.

Exploits (1)

nomisec WRITEUP 13 stars
by duality084 · poc
https://github.com/duality084/CVE-2023-33381-MitraStar-GPT-2741GNAC

Scores

CVSS v3 7.2
EPSS 0.5975
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
mitrastar/gpt-2741gnac_firmware ar_g5.8_110wvn0b7_2
Published Jun 06, 2023
Tracked Since Feb 18, 2026