CVE-2023-33239: Second Order Command-injection Vulnerability in the Key-generation Function
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from insufficient input validation in the key-generation function, which could potentially allow malicious users to execute remote code on affected devices.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-33239.
What is the severity of CVE-2023-33239?
The severity of CVE-2023-33239 is critical with a score of 9.8.
Which firmware versions are affected by CVE-2023-33239?
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are affected by CVE-2023-33239.
What is the cause of CVE-2023-33239?
CVE-2023-33239 is caused by insufficient input validation in the key-generation function.
How can CVE-2023-33239 be exploited?
CVE-2023-33239 can potentially be exploited by malicious users to execute arbitrary commands.