CVE-2023-50383
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `localPin` request's parameter.
Existen tres vulnerabilidades de inyección de comandos del sistema operativo en la funcionalidad boa formWsc de Realtek rtl819x Jungle SDK v3.4.11. Una serie de solicitudes HTTP especialmente manipuladas pueden conducir a la ejecución de comandos arbitrarios. Un atacante puede enviar una serie de solicitudes HTTP para activar estas vulnerabilidades. Esta inyección de comando está relacionada con el parámetro de solicitud "localPin".
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-12-07 CVE Reserved
- 2024-07-08 CVE Published
- 2024-08-02 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1899 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Level1 Search vendor "Level1" | Wbr-6013 Firmware Search vendor "Level1" for product "Wbr-6013 Firmware" | rer4_a_v3411b_2t2r_lev_09_170623 Search vendor "Level1" for product "Wbr-6013 Firmware" and version "rer4_a_v3411b_2t2r_lev_09_170623" | - |
Affected
| in | Level1 Search vendor "Level1" | Wbr-6013 Search vendor "Level1" for product "Wbr-6013" | - | - |
Safe
|
Realtek Search vendor "Realtek" | Rtl819x Jungle Software Development Kit Search vendor "Realtek" for product "Rtl819x Jungle Software Development Kit" | 3.4.11 Search vendor "Realtek" for product "Rtl819x Jungle Software Development Kit" and version "3.4.11" | - |
Affected
|