CVE-2023-46306
HIGHNetModule Router Software <4.6.0.106, 4.8.0.101 - Command Injection
Title source: llmDescription
The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command constructed with unsanitized user input: shell metacharacters in the /admin/gnssAutoAlign.php device_id parameter. This occurs because another thread can be started before the trap that triggers the cleanup function. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. NOTE: this is different from CVE-2023-0861 and CVE-2023-0862, which were fixed in version 4.6.0.105.
References (3)
Core 3
Core References
Product, Third Party Advisory
https://pentest.blog/advisory-netmodule-router-software-race-condition-leads-to-remote-code-execution/
Scores
CVSS v3
8.4
EPSS
0.0096
EPSS Percentile
56.9%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
netmodule/netmodule_router_software
< 4.6.0.105
Published
Oct 22, 2023
Tracked Since
Feb 18, 2026