Record summary

CVE-2023-43478 has a selected CVSS score of 8.8 (high).

Description

fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the configuration on the device, ultimately leading to code execution as root.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 18, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 24, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Smart Modem Gen 2 (Arcadyan LH1000)

Browse Telstra / Smart Modem Gen 2 (Arcadyan LH1000)

Default status: unaffected

CVE ListBefore 0.18.15raffected

Default status: unknown

CVE ListBefore 0.18.15raffected
VulnCheckVersion data not supplied

References

2