Vulnerability Description
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iodata | Wfs-Sr03W Firmware | 1.03 |
| Iodata | Wfs-Sr03W | - |
| Iodata | Wfs-Sr03K Firmware | 1.03 |
| Iodata | Wfs-Sr03K | - |
Related Weaknesses (CWE)
References
- https://sore-pail-31b.notion.site/Command-Injection-2-WFS-SR03-436d09790c2f4e31bExploitThird Party Advisory
- https://sore-pail-31b.notion.site/Command-Injection-2-WFS-SR03-436d09790c2f4e31bExploitThird Party Advisory
FAQ
What is CVE-2023-29805?
CVE-2023-29805 is a vulnerability with a CVSS score of 9.8 (CRITICAL). WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.
How severe is CVE-2023-29805?
CVE-2023-29805 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-29805?
Check the references section above for vendor advisories and patch information. Affected products include: Iodata Wfs-Sr03W Firmware, Iodata Wfs-Sr03W, Iodata Wfs-Sr03K Firmware, Iodata Wfs-Sr03K.