← Volver a CVEs
CVE-2023-0862
HIGH7.2
Descripcion
The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file uploads and deletion. By uploading malicious files to the web root directory, authenticated users could gain remote command execution with elevated privileges. This issue affects NSRW: from 4.3.0.0 before 4.3.0.119, from 4.4.0.0 before 4.4.0.118, from 4.6.0.0 before 4.6.0.105, from 4.7.0.0 before 4.7.0.103.
Detalles CVE
Puntuacion CVSS v3.17.2
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosHIGH
Interaccion usuarioNONE
Publicado2/16/2023
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
netmodule:nb1601netmodule:nb1800netmodule:nb1810netmodule:nb2800netmodule:nb2810netmodule:nb3701netmodule:nb3800netmodule:nb800netmodule:netmodule_router_softwarenetmodule:ng800
Debilidades (CWE)
CWE-22CWE-22
Referencias
https://onekey.com/blog/security-advisory-netmodule-multiple-vulnerabilities/(research@onekey.com)
https://share.netmodule.com/public/system-software/4.7/4.7.0.103/NRSW-RN-4.7.0.103.pdf(research@onekey.com)
https://onekey.com/blog/security-advisory-netmodule-multiple-vulnerabilities/(af854a3a-2127-422b-91ae-364da2661108)
https://share.netmodule.com/public/system-software/4.7/4.7.0.103/NRSW-RN-4.7.0.103.pdf(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.