CVE-2023-20820: Input Validation
Published Sep 4, 2023
·Updated
In wlan service, there is a possible command injection due to improper input validation. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00244189; Issue ID: WCNCR00244189.
Affected Software
15 affected components
OpenWrt OpenWrt=19.07.0
OpenWrt OpenWrt=21.02.0
MediaTek Mt6890
MediaTek Mt7603
MediaTek MT7612
MediaTek MT7613
MediaTek MT7615
MediaTek MT7622
MediaTek Mt7626
MediaTek MT7629
MediaTek MT7915
MediaTek Mt7916
MediaTek Mt7981
MediaTek Mt7986
MediaTek Mt7990
Event History
Sep 4, 2023
CVE Published
via MITRE·02:27 AM
Data Sourced
via MITRE·02:27 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this wlan service vulnerability?
The vulnerability ID for this wlan service vulnerability is CVE-2023-20820.
2
What is the severity rating of CVE-2023-20820?
CVE-2023-20820 has a severity rating of 7.2 (high).
3
Is user interaction required for exploitation of CVE-2023-20820?
No, user interaction is not needed for exploitation of CVE-2023-20820.
4
Which software versions are affected by CVE-2023-20820?
OpenWrt versions 19.07.0 and 21.02.0 are affected by CVE-2023-20820.
5
How can I fix the vulnerability CVE-2023-20820?
To fix the vulnerability CVE-2023-20820, apply the provided patch ID: WCNCR00244189.