Impact
This vulnerability is a command injection flaw in the diagnostic script import feature of the Netlink ICT HG323RW router. An attacker who can authenticate to the web management interface can upload a malicious script and have it executed with root privileges on the device. The result is full compromise of the router, allowing the attacker to modify configuration, intercept traffic, and pivot to other network assets.
Affected Systems
Affected devices are Netlink ICT Pvt Ltd Netlink ICT HG323RW routers, in particular firmware versions up to 3.1.02-260228. The vendor recommends upgrading to firmware 3.1.02-260904 (Internal Build Name: HG323RW_3.7 Netlinkver) to eliminate the flaw.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Exploitation requires authentication through the web interface, but once logged in, the attacker can upload and execute arbitrary OS commands as root. This makes the risk significant for any network hosting affected routers.
OpenCVE Enrichment