7.2

CVE-2023-20820

In wlan service, there is a possible command injection due to improper input validation. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00244189; Issue ID: WCNCR00244189.

Data is provided by the National Vulnerability Database (NVD)
OpenwrtOpenwrt Version19.07.0 Update-
   MediatekMt6890 Version-
   MediatekMt7603 Version-
   MediatekMt7612 Version-
   MediatekMt7613 Version-
   MediatekMt7615 Version-
   MediatekMt7622 Version-
   MediatekMt7626 Version-
   MediatekMt7629 Version-
   MediatekMt7915 Version-
   MediatekMt7916 Version-
   MediatekMt7981 Version-
   MediatekMt7986 Version-
   MediatekMt7990 Version-
OpenwrtOpenwrt Version21.02.0 Update-
   MediatekMt6890 Version-
   MediatekMt7603 Version-
   MediatekMt7612 Version-
   MediatekMt7613 Version-
   MediatekMt7615 Version-
   MediatekMt7622 Version-
   MediatekMt7626 Version-
   MediatekMt7629 Version-
   MediatekMt7915 Version-
   MediatekMt7916 Version-
   MediatekMt7981 Version-
   MediatekMt7986 Version-
   MediatekMt7990 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.1% 0.76
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H