CVE-2023-38863: Command Injection
Published Aug 15, 2023
·Updated
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub410074 function at bin/webmgnt.
Affected Software
2 affected components
Comfast Cf-xr11 Firmware=2.7.2
Comfast CF-XR11
Event History
Aug 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-38863?
CVE-2023-38863 has a severity rating that suggests it can lead to arbitrary code execution.
2
How do I fix CVE-2023-38863?
To mitigate CVE-2023-38863, update the COMFAST CF-XR11 firmware to the latest available version.
3
What software is affected by CVE-2023-38863?
CVE-2023-38863 specifically affects COMFAST CF-XR11 firmware version 2.7.2.
4
What type of vulnerability is CVE-2023-38863?
CVE-2023-38863 is classified as a command injection vulnerability.
5
Can CVE-2023-38863 be exploited remotely?
Yes, CVE-2023-38863 can be exploited remotely due to insufficient input validation.