The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not properly sanitized before being used in a system call, which could allow an authenticated attacker to achieve command injection as root on the device.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2023-19 |
|
History
Tue, 24 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-09-24T19:00:27.334Z
Reserved: 2023-09-18T17:35:17.960Z
Link: CVE-2023-43477
Updated: 2024-08-02T19:44:43.292Z
Status : Modified
Published: 2023-09-20T13:15:12.047
Modified: 2024-11-21T08:24:07.400
Link: CVE-2023-43477
No data.
OpenCVE Enrichment
No data.
Weaknesses