File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget function in the /sbin/cloudadmin.sh component.
References
Link | Resource |
---|---|
https://github.com/Push3AX/vul/blob/main/DCN/DCFW_1800_SDC_CommandInjection.md | Exploit Third Party Advisory |
https://www.dcnetworks.com.cn/goods/61.html | Product |
Configurations
Configuration 1 (hide)
AND |
|
History
10 Oct 2023, 20:00
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-434 | |
References | (MISC) https://github.com/Push3AX/vul/blob/main/DCN/DCFW_1800_SDC_CommandInjection.md - Exploit, Third Party Advisory | |
References | (MISC) https://www.dcnetworks.com.cn/goods/61.html - Product | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CPE | cpe:2.3:o:dcnetworks:dcfw-1800-sdc_firmware:3.0:*:*:*:*:*:*:* cpe:2.3:h:dcnetworks:dcfw-1800-sdc:-:*:*:*:*:*:*:* |
|
First Time |
Dcnetworks dcfw-1800-sdc Firmware
Dcnetworks dcfw-1800-sdc Dcnetworks |
04 Oct 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-04 22:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-43321
Mitre link : CVE-2023-43321
CVE.ORG link : CVE-2023-43321
JSON object : View
Products Affected
dcnetworks
- dcfw-1800-sdc_firmware
- dcfw-1800-sdc
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type