CVE-2023-23295: Command Injection
Published Feb 23, 2023
·Updated
Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.
Affected Software
59 affected components
Korenix Jetwave 2212g Firmware=1.3.t
Korenix Jetwave 2212g
Korenix Jetwave 2212x Firmware=1.3.0
Korenix Jetwave 2212x
Korenix Jetwave 2212s Firmware=1.3.0
Korenix Jetwave 2212s
Korenix Jetwave 2211c Firmware<1.6
Korenix Jetwave 2211c
Korenix Jetwave 2411 Firmware<1.5
Korenix Jetwave 2411
Korenix Jetwave 2111 Firmware<1.5
Korenix Jetwave 2111
Korenix Jetwave 2411l Firmware<1.6
Korenix Jetwave 2411l
Korenix Jetwave 2111l Firmware<1.6
Korenix Jetwave 2111l
Korenix Jetwave 2414 Firmware<1.4
Korenix Jetwave 2414
Korenix Jetwave 2114 Firmware<1.4
Korenix Jetwave 2114
Korenix Jetwave 2424 Firmware<1.3
Korenix Jetwave 2460 Firmware<1.6
Korenix Jetwave 2460
Korenix Jetwave 4221hp-e Firmware<=1.3.0
Korenix Jetwave 4221hp-e
Korenix Jetwave 3220 V3 Firmware<1.7
Korenix Jetwave 3220 V3
Korenix Jetwave 3420 V3 Firmware<1.7
Korenix Jetwave 3420 V3
All of the following
Korenix Jetwave 2212g Firmware=1.3.t
Korenix Jetwave 2212g
All of the following
Korenix Jetwave 2212x Firmware=1.3.0
Korenix Jetwave 2212x
All of the following
Korenix Jetwave 2212s Firmware=1.3.0
Korenix Jetwave 2212s
All of the following
Korenix Jetwave 2211c Firmware<1.6
Korenix Jetwave 2211c
All of the following
Korenix Jetwave 2411 Firmware<1.5
Korenix Jetwave 2411
All of the following
Korenix Jetwave 2111 Firmware<1.5
Korenix Jetwave 2111
All of the following
Korenix Jetwave 2411l Firmware<1.6
Korenix Jetwave 2411l
All of the following
Korenix Jetwave 2111l Firmware<1.6
Korenix Jetwave 2111l
All of the following
Korenix Jetwave 2414 Firmware<1.4
Korenix Jetwave 2414
All of the following
Korenix Jetwave 2114 Firmware<1.4
Korenix Jetwave 2114
All of the following
Korenix Jetwave 2424 Firmware<1.3
Korenix Jetwave 2414
All of the following
Korenix Jetwave 2460 Firmware<1.6
Korenix Jetwave 2460
All of the following
Korenix Jetwave 4221hp-e Firmware<=1.3.0
Korenix Jetwave 4221hp-e
All of the following
Korenix Jetwave 3220 V3 Firmware<1.7
Korenix Jetwave 3220 V3
All of the following
Korenix Jetwave 3420 V3 Firmware<1.7
Korenix Jetwave 3420 V3
Event History
Feb 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-23295.
2
What is the severity of CVE-2023-23295?
The severity of CVE-2023-23295 is high (8.8 out of 10).
3
Which software versions are affected by CVE-2023-23295?
Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are affected by CVE-2023-23295.
4
How does CVE-2023-23295 work?
An attacker can modify the sysCmd parameter in /goform/formSysCmd to execute commands as root, allowing command injection.
5
Is Korenix Jetwave 2212g firmware 1.3.t vulnerable to CVE-2023-23295?
Yes, Korenix Jetwave 2212g firmware 1.3.t is vulnerable to CVE-2023-23295.