CVE-2023-49254

HIGH

Network Test Tools - Command Injection

Title source: llm
STIX 2.1

Description

Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field of the network test tools. This is similar to the vulnerability CVE-2021-28151 mitigated on the user interface level by blacklisting characters with JavaScript, however, it can still be exploited by sending POST requests directly.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://cert.pl/en/posts/2024/01/CVE-2023-49253/
Third Party Advisory third-party-advisory
https://cert.pl/posts/2024/01/CVE-2023-49253/

Scores

CVSS v3 8.8
EPSS 0.0073
EPSS Percentile 49.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
hongdian/h8951-4g-esp_firmware < 2310271149
Published Jan 12, 2024
Tracked Since Feb 18, 2026