Description
Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.
Published: 2023-02-23
Score: 8.8 High
EPSS: 2.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-27395 Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.
History

Mon, 17 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Korenix Jetwave 2111 Jetwave 2111 Firmware Jetwave 2111l Jetwave 2111l Firmware Jetwave 2114 Jetwave 2114 Firmware Jetwave 2211c Jetwave 2211c Firmware Jetwave 2212g Jetwave 2212g Firmware Jetwave 2212s Jetwave 2212s Firmware Jetwave 2212x Jetwave 2212x Firmware Jetwave 2411 Jetwave 2411 Firmware Jetwave 2411l Jetwave 2411l Firmware Jetwave 2414 Jetwave 2414 Firmware Jetwave 2424 Firmware Jetwave 2460 Jetwave 2460 Firmware Jetwave 3220 V3 Jetwave 3220 V3 Firmware Jetwave 3420 V3 Jetwave 3420 V3 Firmware Jetwave 4221hp-e Jetwave 4221hp-e Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-17T18:30:19.190Z

Reserved: 2023-01-11T00:00:00.000Z

Link: CVE-2023-23295

cve-icon Vulnrichment

Updated: 2024-08-02T10:28:40.814Z

cve-icon NVD

Status : Modified

Published: 2023-02-23T23:15:10.947

Modified: 2025-03-17T19:15:18.787

Link: CVE-2023-23295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses