9.8

CVE-2023-26866

GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respectively are vulnerable to remote command injection. Commands are executed using pre-login execution and executed with root privileges allowing complete takeover.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Greenpacket ≫ Wr-1200 Firmware Version m-idu-1.6.0.3_v1.1
   Greenpacket ≫ Wr-1200 Version -
Greenpacket ≫ Ot-235 Firmware Version m-idu-1.6.0.3_v1.1
   Greenpacket ≫ Ot-235 Version -
Greenpacket ≫ Ot-235 Firmware Version mh-46360-2.0.3-r5-gp
   Greenpacket ≫ Ot-235 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.29% 0.809
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://github.com/lionelmusonza/CVE-2023-26866
Third Party Advisory