Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Korenix
Subscribe
|
Jetwave 2111
Subscribe
Jetwave 2111 Firmware
Subscribe
Jetwave 2111l
Subscribe
Jetwave 2111l Firmware
Subscribe
Jetwave 2114
Subscribe
Jetwave 2114 Firmware
Subscribe
Jetwave 2211c
Subscribe
Jetwave 2211c Firmware
Subscribe
Jetwave 2212g
Subscribe
Jetwave 2212g Firmware
Subscribe
Jetwave 2212s
Subscribe
Jetwave 2212s Firmware
Subscribe
Jetwave 2212x
Subscribe
Jetwave 2212x Firmware
Subscribe
Jetwave 2411
Subscribe
Jetwave 2411 Firmware
Subscribe
Jetwave 2411l
Subscribe
Jetwave 2411l Firmware
Subscribe
Jetwave 2414
Subscribe
Jetwave 2414 Firmware
Subscribe
Jetwave 2424 Firmware
Subscribe
Jetwave 2460
Subscribe
Jetwave 2460 Firmware
Subscribe
Jetwave 3220 V3
Subscribe
Jetwave 3220 V3 Firmware
Subscribe
Jetwave 3420 V3
Subscribe
Jetwave 3420 V3 Firmware
Subscribe
Jetwave 4221hp-e
Subscribe
Jetwave 4221hp-e Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-27395 | Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-17T18:30:19.190Z
Reserved: 2023-01-11T00:00:00.000Z
Link: CVE-2023-23295
Updated: 2024-08-02T10:28:40.814Z
Status : Modified
Published: 2023-02-23T23:15:10.947
Modified: 2025-03-17T19:15:18.787
Link: CVE-2023-23295
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD