CVE-2023-23294
23.02.2023, 23:15
Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.
Vendor | Product | Version |
---|---|---|
korenix | jetwave_2212g_firmware | 1.3.t:t |
korenix | jetwave_2212x_firmware | 1.3.0 |
korenix | jetwave_2212s_firmware | 1.3.0 |
korenix | jetwave_2211c_firmware | 𝑥 < 1.6 |
korenix | jetwave_2411_firmware | 𝑥 < 1.5 |
korenix | jetwave_2111_firmware | 𝑥 < 1.5 |
korenix | jetwave_2411l_firmware | 𝑥 < 1.6 |
korenix | jetwave_2111l_firmware | 𝑥 < 1.6 |
korenix | jetwave_2414_firmware | 𝑥 < 1.4 |
korenix | jetwave_2114_firmware | 𝑥 < 1.4 |
korenix | jetwave_2424_firmware | 𝑥 < 1.3 |
korenix | jetwave_2460_firmware | 𝑥 < 1.6 |
korenix | jetwave_4221hp-e__firmware | 𝑥 ≤ 1.3.0 |
korenix | jetwave_3220_v3__firmware | 𝑥 < 1.7 |
korenix | jetwave_3420_v3__firmware | 𝑥 < 1.7 |
𝑥
= Vulnerable software versions