CVE-2023-43893: OS Command Injection
Published Oct 2, 2023
·Updated
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeupmac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.
Affected Software
2 affected components
netis-systems N3m Firmware=1.0.1.865
netis-systems N3m=v2
Event History
Oct 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-43893.
2
What is the severity of CVE-2023-43893?
The severity of CVE-2023-43893 is critical with a CVSS score of 9.8.
3
How does the vulnerability in Netis N3Mv2-V1.0.1.865 occur?
The vulnerability in Netis N3Mv2-V1.0.1.865 occurs due to a command injection via the wakeup_mac parameter in the Wake-On-LAN (WoL) function.
4
How can this vulnerability be exploited?
This vulnerability can be exploited using a crafted payload.
5
Is there a fix available for this vulnerability?
There is no information available regarding a fix for this vulnerability at the moment.