CVE-2023-41029

Command injection vulnerability in thehomemng.htm endpointinJuplink RX4-1500 Wifi router firmware versionsV1.0.2,V1.0.3,V1.0.4, andV1.0.5allows authenticated remote attackers to execute commands as root via specially crafted HTTP requests to the vulnerable endpoint.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
XICNA
8 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---