CVE-2023-31985: Command Injection
Published May 12, 2023
·Updated
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NSv4 allows attacker to execute arbitrary code via the formAccept function in /bin/webs without any limitations.
Affected Software
4 affected components
Edimax Br-6428ns Firmware=1.10
Edimax BR-6428NS=v4
All of the following
Edimax Br-6428ns Firmware=1.10
Edimax BR-6428NS=v4
Event History
May 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability associated with CVE-2023-31985?
CVE-2023-31985 describes a Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 that allows attackers to execute arbitrary code.
2
What are the affected versions related to CVE-2023-31985?
The affected version for CVE-2023-31985 is Edimax BR-6428NS Firmware version 1.10.
3
How can I mitigate the risk posed by CVE-2023-31985?
To mitigate CVE-2023-31985, users should upgrade their firmware to a version higher than 1.10 if available.
4
What can an attacker achieve with CVE-2023-31985?
An attacker exploiting CVE-2023-31985 can execute arbitrary code on the affected Edimax router.
5
Is CVE-2023-31985 exploitable remotely?
Yes, CVE-2023-31985 can be exploited remotely without any restrictions.