CVE-2023-46510: OS Command Injection
Published Oct 27, 2023
·Updated
An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.
Affected Software
2 affected components
All of the following
ZIONCOM A7000r Firmware=4.1cu.4154
ZIONCOM A7000R
Event History
Oct 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-46510.
2
What is the severity of CVE-2023-46510?
The severity of CVE-2023-46510 is critical.
3
What is the affected software version?
The affected software version is Zioncom A7000r Firmware 4.1cu.4154.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by executing arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.
5
Is there a fix available for CVE-2023-46510?
Please refer to the provided reference link for any available fixes for CVE-2023-46510.