Command injection in the network test tools
Vulnerability Description
Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field of the network test tools. This is similar to the vulnerability CVE-2021-28151 mitigated on the user interface level by blacklisting characters with JavaScript, however, it can still be exploited by sending POST requests directly.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-49254
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Robert Pogorzelski (SEQRED)
References
More from Hongdian
View All →Affected Vendor
Hongdian
View all reports →