CVE-2023-43477

MEDIUM

Telstra Smart Modem Gen 2 - Command Injection

Title source: llm
STIX 2.1

Description

The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not properly sanitized before being used in a system call, which could allow an authenticated attacker to achieve command injection as root on the device. 

References (1)

Core 1
Core References

Scores

CVSS v3 6.8
EPSS 0.1575
EPSS Percentile 96.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
telstra/arcadyan_lh1000_firmware < 0.18.15r
Published Sep 20, 2023
Tracked Since Feb 18, 2026