CVE-2023-23295

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
23/02/2023
Last modified:
17/03/2025

Description

Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:korenix:jetwave_2212g_firmware:1.3.t:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2212g:-:*:*:*:*:*:*:*
cpe:2.3:o:korenix:jetwave_2212x_firmware:1.3.0:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2212x:-:*:*:*:*:*:*:*
cpe:2.3:o:korenix:jetwave_2212s_firmware:1.3.0:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetwave_2212s:-:*:*:*:*:*:*:*
cpe:2.3:o:korenix:jetwave_2211c_firmware:*:*:*:*:*:*:*:* 1.6 (excluding)
cpe:2.3:h:korenix:jetwave_2211c:-:*:*:*:*:*:*:*
cpe:2.3:o:korenix:jetwave_2411_firmware:*:*:*:*:*:*:*:* 1.5 (excluding)
cpe:2.3:h:korenix:jetwave_2411:-:*:*:*:*:*:*:*
cpe:2.3:o:korenix:jetwave_2111_firmware:*:*:*:*:*:*:*:* 1.5 (excluding)
cpe:2.3:h:korenix:jetwave_2111:-:*:*:*:*:*:*:*
cpe:2.3:o:korenix:jetwave_2411l_firmware:*:*:*:*:*:*:*:* 1.6 (excluding)
cpe:2.3:h:korenix:jetwave_2411l:-:*:*:*:*:*:*:*
cpe:2.3:o:korenix:jetwave_2111l_firmware:*:*:*:*:*:*:*:* 1.6 (excluding)