CVE-2023-43891: Command Injection
Published Oct 2, 2023
·Updated
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.
Affected Software
2 affected components
netis-systems N3m Firmware=1.0.1.865
netis-systems N3m=v2
Event History
Oct 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-43891.
2
What software is affected by this vulnerability?
Netis N3Mv2-V1.0.1.865 firmware version 1.0.1.865 is affected by this vulnerability.
3
What is the severity of CVE-2023-43891?
The severity of CVE-2023-43891 is critical with a CVSS score of 9.8.
4
How can the vulnerability be exploited?
The vulnerability can be exploited via a crafted payload in the Changing Username and Password function.
5
Is there a fix available for CVE-2023-43891?
No information is available regarding a fix for CVE-2023-43891 at this time.