TROYANOSYVIRUS
Retour aux CVEs

CVE-2023-46306

HIGH
8.4

Description

The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command constructed with unsanitized user input: shell metacharacters in the /admin/gnssAutoAlign.php device_id parameter. This occurs because another thread can be started before the trap that triggers the cleanup function. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. NOTE: this is different from CVE-2023-0861 and CVE-2023-0862, which were fixed in version 4.6.0.105.

Details CVE

Score CVSS v3.18.4
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Vecteur d'attaqueADJACENT_NETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie10/22/2023
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

netmodule:nb1601netmodule:nb1800netmodule:nb1810netmodule:nb2800netmodule:nb2810netmodule:nb3701netmodule:nb3800netmodule:netmodule_router_softwarenetmodule:ng800

Faiblesses (CWE)

CWE-78CWE-78

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.