nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-43478 CVE-2023-43478
HIGH
Unauthenticated configuration restore and firmware update
Record summary
CVE-2023-43478 has a selected CVSS score of 8.8 (high).
Description
fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the configuration on the device, ultimately leading to code execution as root.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 18, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 24, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Smart Modem Gen 2 (Arcadyan LH1000)Browse Telstra / Smart Modem Gen 2 (Arcadyan LH1000)Default status: unaffected | CVE List | Before 0.18.15r | affected |
arcadyan_lh1000Browse telstra / arcadyan_lh1000Default status: unknown | CVE List | Before 0.18.15r | affected |
arcadyan_lh1000_firmwareBrowse telstra / arcadyan_lh1000_firmware | VulnCheck | Version data not supplied | |
References
2tenable.com
https://www.tenable.com/security/research/tra-2023-19