CVE-2023-23295

Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:korenix:jetwave_2212g_firmware:1.3.t:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2212g:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:korenix:jetwave_2212x_firmware:1.3.0:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2212x:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:korenix:jetwave_2212s_firmware:1.3.0:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2212s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:korenix:jetwave_2211c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2211c:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:korenix:jetwave_2411_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2411:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:korenix:jetwave_2111_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2111:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:korenix:jetwave_2411l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2411l:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:korenix:jetwave_2111l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2111l:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:korenix:jetwave_2414_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2414:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:korenix:jetwave_2114_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2114:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:korenix:jetwave_2424_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2414:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:korenix:jetwave_2460_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2460:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:korenix:jetwave_4221hp-e__firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_4221hp-e:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:korenix:jetwave_3220_v3__firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_3220_v3:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:korenix:jetwave_3420_v3__firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_3420_v3:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-02-23 23:15

Updated : 2024-02-28 19:51


NVD link : CVE-2023-23295

Mitre link : CVE-2023-23295

CVE.ORG link : CVE-2023-23295


JSON object : View

Products Affected

korenix

  • jetwave_2114
  • jetwave_2212s
  • jetwave_4221hp-e
  • jetwave_2212g
  • jetwave_2414
  • jetwave_2460_firmware
  • jetwave_2411l
  • jetwave_3420_v3__firmware
  • jetwave_2111l_firmware
  • jetwave_4221hp-e__firmware
  • jetwave_2211c
  • jetwave_2212g_firmware
  • jetwave_2111_firmware
  • jetwave_3420_v3
  • jetwave_3220_v3__firmware
  • jetwave_2411_firmware
  • jetwave_2460
  • jetwave_2212x
  • jetwave_2212s_firmware
  • jetwave_2414_firmware
  • jetwave_2111
  • jetwave_2411l_firmware
  • jetwave_2424_firmware
  • jetwave_2211c_firmware
  • jetwave_2212x_firmware
  • jetwave_2114_firmware
  • jetwave_2411
  • jetwave_2111l
  • jetwave_3220_v3
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')