Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-27395 Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 17 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-17T18:30:19.190Z

Reserved: 2023-01-11T00:00:00.000Z

Link: CVE-2023-23295

cve-icon Vulnrichment

Updated: 2024-08-02T10:28:40.814Z

cve-icon NVD

Status : Modified

Published: 2023-02-23T23:15:10.947

Modified: 2025-03-17T19:15:18.787

Link: CVE-2023-23295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.