CVE Published: 22/09/2023 |
CVE Updated: 24/09/2024 |
CVE Year: 2023 Source: XI |
Vendor: Juplink |
Product: RX4-1500 Status : PUBLISHED
CVE-2023-41029 Description
Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows authenticated remote attackers to execute commands as root via specially crafted HTTP requests to the vulnerable endpoint.
Metrics
CVSS Version: 3.1 |
Base Score: 8 HIGH Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H