Record summary

CVE-2023-50382 has a selected CVSS score of 7.2 (high).

Description

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `peerPin` request's parameter.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 24, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListRER4_A_v3411b_2T2R_LEV_09_170623affected
rer4_a_v3411b_2t2r_lev_09_170623affected
CVE Listv3.4.11affected

Default status: unknown

CVE List3.4.11affected

References

3