Post-Auth Command Injection in Telstra Smart Modem Gen 2 (Arcadyan LH1000)
Vulnerability Description
The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not properly sanitized before being used in a system call, which could allow an authenticated attacker to achieve command injection as root on the device.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-43477
Credits & Attribution
No credits recorded in the NVD database.
Affected Vendor
Telstra
View all reports →