CVE-2023-41012

An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:chinamobile:intelligent_home_gateway_firmware:hg6543c4:*:*:*:*:*:*:*
cpe:2.3:h:chinamobile:intelligent_home_gateway:-:*:*:*:*:*:*:*

History

11 Sep 2023, 17:32

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://github.com/te5tb99/For-submitting/wiki/Command-Execution-Vulnerability-in-China-Mobile-Intelligent-Home-Gateway-HG6543C4-Identity-verification-has-design-flaws - (MISC) https://github.com/te5tb99/For-submitting/wiki/Command-Execution-Vulnerability-in-China-Mobile-Intelligent-Home-Gateway-HG6543C4-Identity-verification-has-design-flaws - Exploit, Third Party Advisory
First Time Chinamobile intelligent Home Gateway
Chinamobile intelligent Home Gateway Firmware
Chinamobile
CWE CWE-384
CPE cpe:2.3:o:chinamobile:intelligent_home_gateway_firmware:hg6543c4:*:*:*:*:*:*:*
cpe:2.3:h:chinamobile:intelligent_home_gateway:-:*:*:*:*:*:*:*

05 Sep 2023, 17:31

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-05 16:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-41012

Mitre link : CVE-2023-41012

CVE.ORG link : CVE-2023-41012


JSON object : View

Products Affected

chinamobile

  • intelligent_home_gateway
  • intelligent_home_gateway_firmware
CWE
CWE-384

Session Fixation