CVE-2023-3333: OS Command Injection
Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to execute an arbitrary OS command with the root privilege, after obtaining a high privilege exploiting CVE-2023-3330 and CVE-2023-3331 vulnerabilities.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3333?
CVE-2023-3333 is an Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm routers.
Which NEC Corporation Aterm routers are affected by CVE-2023-3333?
NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N, and WR8170N routers are affected by CVE-2023-3333.
What is the severity of CVE-2023-3333?
CVE-2023-3333 has a severity rating of 7.2 (High).
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The CWE ID for CVE-2023-3333 is 78.
How do I fix CVE-2023-3333?
To fix CVE-2023-3333, update your NEC Corporation Aterm router firmware to the latest version provided by NEC.