Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-50383


Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `localPin` request's parameter.


Published

2024-07-08T16:15:07.327

Last Modified

2024-11-21T08:36:56.687

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application realtek rtl819x_jungle_software_development_kit 3.4.11 Yes
Operating System level1 wbr-6013_firmware rer4_a_v3411b_2t2r_lev_09_170623 Yes
Hardware level1 wbr-6013 - No

References