CVE-2023-38862: Command Injection
Published Aug 15, 2023
·Updated
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub431F64 function in bin/webmgnt.
Affected Software
2 affected components
Comfast Cf-xr11 Firmware=2.7.2
Comfast CF-XR11
Event History
Aug 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-38862?
The severity of CVE-2023-38862 is high due to its potential for arbitrary code execution.
2
How do I fix CVE-2023-38862?
To fix CVE-2023-38862, update the Comfast CF-XR11 firmware to a version that addresses this vulnerability.
3
Which versions of Comfast CF-XR11 are affected by CVE-2023-38862?
CVE-2023-38862 specifically affects Comfast CF-XR11 firmware version 2.7.2.
4
What type of vulnerability is CVE-2023-38862?
CVE-2023-38862 is a code execution vulnerability that allows attackers to execute arbitrary code.
5
What is the impact of CVE-2023-38862?
The impact of CVE-2023-38862 can lead to complete system compromise by allowing unauthorized code execution.