CVE-2017-2141: OS Command Injection
Published Apr 28, 2017
·Updated
WN-G300R3 firmware 1.03 and earlier allows attackers with administrator rights to execute arbitrary OS commands via unspecified vectors.
Affected Software
2 affected components
Iodata Wn-g300r3 Firmware<=1.03
Iodata Wn-g300r3
Event History
Apr 28, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-2141?
CVE-2017-2141 has a critical severity due to its potential to allow remote code execution by attackers with administrator rights.
2
How do I fix CVE-2017-2141?
To fix CVE-2017-2141, update the WN-G300R3 firmware to a version later than 1.03.
3
What devices are affected by CVE-2017-2141?
CVE-2017-2141 affects the Iodata WN-G300R3 with firmware versions 1.03 and earlier.
4
What can attackers do through CVE-2017-2141?
Attackers with administrator rights can execute arbitrary operating system commands through CVE-2017-2141.
5
Is there a workaround for CVE-2017-2141?
Currently, the only recommended approach to mitigate CVE-2017-2141 is to update the device's firmware.