CVE-2023-38829: Command Injection
Published Sep 11, 2023
·Updated
An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnostic tools component in the admin management interface.
Affected Software
2 affected components
netis-systems Wf2409e Firmware=3.6.42541
netis-systems Wf2409e
Event History
Sep 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-38829.
2
What is the severity of CVE-2023-38829?
The severity of CVE-2023-38829 is high with a severity value of 8.8.
3
How does CVE-2023-38829 allow remote code execution?
CVE-2023-38829 allows a remote attacker to execute arbitrary code through the ping and traceroute functions of the diagnostic tools component in the admin management interface.
4
Which software versions are affected by CVE-2023-38829?
The Netis-systems Wf2409e Firmware version 3.6.42541 is affected by CVE-2023-38829.
5
Is Netis-systems Wf2409e vulnerable to CVE-2023-38829?
No, Netis-systems Wf2409e is not vulnerable to CVE-2023-38829.