CVE-2023-38861: Command Injection
Published Aug 15, 2023
·Updated
An issue in Wavlink WLWNJ575A3 v.R75A3V1410220513 allows a remote attacker to execute arbitrary code via username parameter of the setsysadm function in adm.cgi.
Affected Software
2 affected components
Wavlink Wl-wn575a3 Firmware=r75a3_v1410_220513
Wavlink WL-WN575A3
Event History
Aug 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-38861.
2
What is the severity of CVE-2023-38861?
The severity of CVE-2023-38861 is critical.
3
How does CVE-2023-38861 allow an attacker to execute arbitrary code?
CVE-2023-38861 allows a remote attacker to execute arbitrary code via the username parameter of the set_sys_adm function in adm.cgi in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513.
4
Is Wavlink WL-WN575A3 vulnerable to CVE-2023-38861?
Yes, Wavlink WL-WN575A3 with firmware version r75a3_v1410_220513 is vulnerable to CVE-2023-38861.
5
How can I fix CVE-2023-38861?
To fix CVE-2023-38861, it is recommended to apply the latest firmware update provided by Wavlink.