CVE-2023-29805: OS Command Injection
Published Apr 14, 2023
·Updated
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the prostorcanceltranshandlerpart19 function.
Affected Software
8 affected components
Iodata Wfs-sr03w Firmware=1.03
Iodata Wfs-sr03w
Iodata Wfs-sr03k Firmware=1.03
Iodata Wfs-sr03k
All of the following
Iodata Wfs-sr03w Firmware=1.03
Iodata Wfs-sr03w
All of the following
Iodata Wfs-sr03k Firmware=1.03
Iodata Wfs-sr03k
Event History
Apr 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-29805?
CVE-2023-29805 is a command injection vulnerability found in WFS-SR03 v1.0.3.
2
How severe is CVE-2023-29805?
The severity of CVE-2023-29805 is rated as critical with a severity value of 9.8.
3
What software versions are affected by CVE-2023-29805?
Versions 1.0.3 of Iodata Wfs-sr03w Firmware and Iodata Wfs-sr03k Firmware are affected by CVE-2023-29805.
4
How can I fix the CVE-2023-29805 vulnerability?
To fix the CVE-2023-29805 vulnerability, users should update the affected WFS-SR03 firmware to a version that is not vulnerable.
5
Where can I find more information about CVE-2023-29805?
More information about CVE-2023-29805 can be found at the following reference: https://sore-pail-31b.notion.site/Command-Injection-2-WFS-SR03-436d09790c2f4e31b197c39711e17775