fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the configuration on the device, ultimately leading to code execution as root.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.tenable.com/security/research/tra-2023-19 |
History
Tue, 24 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: tenable
Published: 2023-09-20T13:03:10.299Z
Updated: 2024-09-24T18:58:06.387Z
Reserved: 2023-09-18T17:35:17.960Z
Link: CVE-2023-43478
Vulnrichment
Updated: 2024-08-02T19:44:42.240Z
NVD
Status : Modified
Published: 2023-09-20T14:15:15.127
Modified: 2024-11-21T08:24:07.540
Link: CVE-2023-43478
Redhat
No data.