CVE-2023-38864: Command Injection
Published Aug 15, 2023
·Updated
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protaldeletepicname parameter in the sub41171C function at bin/webmgnt.
Affected Software
2 affected components
Comfast Cf-xr11 Firmware=2.7.2
Comfast CF-XR11
Event History
Aug 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-38864?
CVE-2023-38864 has a high severity rating due to the potential for executing arbitrary code.
2
How do I fix CVE-2023-38864?
To fix CVE-2023-38864, upgrade the firmware of Comfast CF-XR11 to a version that addresses this vulnerability.
3
What software versions are affected by CVE-2023-38864?
CVE-2023-38864 affects Comfast CF-XR11 firmware version 2.7.2.
4
What are the potential impacts of CVE-2023-38864?
Exploitation of CVE-2023-38864 can allow an attacker to execute arbitrary code on the affected device.
5
How can I check if my device is vulnerable to CVE-2023-38864?
Verify if your Comfast CF-XR11 uses firmware version 2.7.2, as this version is known to be vulnerable to CVE-2023-38864.