CVE-2023-31986: Command Injection
Published May 15, 2023
·Updated
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NSv4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations.
Affected Software
4 affected components
Edimax Br-6428ns Firmware=1.10
Edimax BR-6428NS=v4
All of the following
Edimax Br-6428ns Firmware=1.10
Edimax BR-6428NS=v4
Event History
May 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-31986?
The severity of CVE-2023-31986 is high due to the potential for command injection and remote code execution.
2
How do I fix CVE-2023-31986?
To fix CVE-2023-31986, you should update the Edimax Wireless Router N300 Firmware to the latest version available.
3
Which version of Edimax Firmware is affected by CVE-2023-31986?
CVE-2023-31986 affects Edimax Wireless Router N300 Firmware version 1.10.
4
Can an attacker exploit CVE-2023-31986 remotely?
Yes, an attacker can exploit CVE-2023-31986 remotely via the vulnerable setWAN function.
5
What devices are impacted by CVE-2023-31986?
CVE-2023-31986 specifically impacts the Edimax BR-6428NS device running the affected firmware.