CVE-2023-46681
HIGHVR-S1000 <2.37 - Command Injection
Title source: llmDescription
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an authenticated attacker who can access to the product's command line interface to execute an arbitrary command.
Scores
CVSS v3
7.8
EPSS
0.0009
EPSS Percentile
25.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-88
Status
published
Affected Products (1)
buffalo/vr-s1000_firmware
< 2.37
Timeline
Published
Dec 26, 2023
Tracked Since
Feb 18, 2026