CVE-2023-38865: Command Injection
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38865?
CVE-2023-38865 is considered a critical vulnerability due to its command injection capabilities.
How do I fix CVE-2023-38865?
To mitigate CVE-2023-38865, upgrade the Comfast CF-XR11 firmware to the latest version provided by the vendor.
What does CVE-2023-38865 affect?
CVE-2023-38865 specifically affects the Comfast CF-XR11 firmware version 2.7.2.
What is command injection in the context of CVE-2023-38865?
In the context of CVE-2023-38865, command injection allows attackers to execute arbitrary commands on the server via manipulated POST requests.
What are the potential impacts of CVE-2023-38865?
The potential impacts of CVE-2023-38865 include unauthorized access, data breaches, and system compromise due to arbitrary command execution.