github.com
https://github.com/te5tb99/For-submitting/wiki/Command-Execution-Vulnerability-in-China-Mobile-Intelligent-Home-Gateway-HG6543C4 CVE-2023-41011
CRITICAL
chinamobile intelligent_home_gateway_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2023-41011 has a selected CVSS score of 9.8 (critical).
Description
Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the shortcut_telnet.cg component.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 19, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
china_mobile_intelligent_home_gatewayBrowse china_mobile_communications / china_mobile_intelligent_home_gatewayDefault status: unknown | CVE List | v.hg6543c4 | affected |
intelligent_home_gateway_firmwareBrowse chinamobile / intelligent_home_gateway_firmware | VulnCheck | Version data not supplied | |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-41011