Back to Database
Status published
Unknown
CVE-2023-49257
Command execution using the certificate upload utility
Vulnerability Description
An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-49257
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Robert Pogorzelski (SEQRED)
References
More from Hongdian
View All →CVE-2023-49262
Buffer overflow vulnerability in Cookie authentication field
Unknown
0
CVE-2023-49261
Sensitive authentication-related value accessible publicly
Unknown
0
CVE-2023-49260
Stored cross-site scripting vulnerability
Unknown
0
CVE-2023-49259
Bruteforcing authentication cookie for a given user
Unknown
0
CVE-2023-49258
Reflected cross-site scripting vulnerability
Unknown
0
Affected Vendor
Hongdian
View all reports →Affected Software
H8951-4G-ESP
Vulnerable Versions:
0
Timeline
Official Publish:
January 12th, 2024
Last Modified:
June 11th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available