CVE-2023-38866: Command Injection
Published Aug 15, 2023
·Updated
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and displayname.
Affected Software
2 affected components
Comfast Cf-xr11 Firmware=2.7.2
Comfast CF-XR11
Event History
Aug 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-38866?
CVE-2023-38866 has a high severity rating due to its command injection vulnerability.
2
How do I fix CVE-2023-38866?
To fix CVE-2023-38866, update the Comfast CF-XR11 firmware to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2023-38866?
CVE-2023-38866 specifically affects Comfast CF-XR11 firmware version 2.7.2.
4
What type of attack can be executed through CVE-2023-38866?
CVE-2023-38866 allows attackers to perform command injection attacks through crafted POST requests.
5
What are the potential impacts of CVE-2023-38866?
The impact of CVE-2023-38866 includes unauthorized execution of commands, which can lead to system compromise.