CVE-2023-40146

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
17/04/2024
Last modified:
04/11/2025

Description

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials and execute unblocked default busybox functionality to trigger this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:peplink:smart_reader_firmware:1.2.0:*:*:*:*:*:*:*
cpe:2.3:h:peplink:smart_reader:-:*:*:*:*:*:*:*