Record summary

CVE-2023-50381 has a selected CVSS score of 7.2 (high).

Description

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `targetAPSsid` request's parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 15, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 24, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListRER4_A_v3411b_2T2R_LEV_09_170623affected
rer4_a_v3411b_2t2r_lev_09_170623affected
CVE Listv3.4.11affected

rtl819x_jungle_software_development_kit

Browse realtek / rtl819x_jungle_software_development_kit
VulnCheckVersion data not supplied

Default status: unknown

CVE List3.4.11affected

References

3