HIGH · 8.8

CVE-2023-39222

OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command that is not intended to be executed from the web ...

Vulnerability Description

OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command that is not intended to be executed from the web interface by sending a specially crafted request. Affected products and versions are as follows: ACERA 1320 firmware ver.01.26 and earlier, ACERA 1310 firmware ver.01.26 and earlier, ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
FurunosystemsAcera 1310 Firmware<= 01.26
FurunosystemsAcera 1310-
FurunosystemsAcera 1320 Firmware<= 01.26
FurunosystemsAcera 1320-
FurunosystemsAcera 1210 Firmware<= 02.36
FurunosystemsAcera 1210-
FurunosystemsAcera 1150I Firmware<= 01.35
FurunosystemsAcera 1150I-
FurunosystemsAcera 1150W Firmware<= 01.35
FurunosystemsAcera 1150W-
FurunosystemsAcera 1110 Firmware<= 01.76
FurunosystemsAcera 1110-
FurunosystemsAcera 1020 Firmware<= 01.86
FurunosystemsAcera 1020-
FurunosystemsAcera 1010 Firmware<= 01.86
FurunosystemsAcera 1010-
FurunosystemsAcera 950 Firmware<= 01.60
FurunosystemsAcera 950-
FurunosystemsAcera 850F Firmware<= 01.60
FurunosystemsAcera 850F-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-39222?

CVE-2023-39222 is a vulnerability with a CVSS score of 8.8 (HIGH). OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command that is not intended to be executed from the web ...

How severe is CVE-2023-39222?

CVE-2023-39222 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-39222?

Check the references section above for vendor advisories and patch information. Affected products include: Furunosystems Acera 1310 Firmware, Furunosystems Acera 1310, Furunosystems Acera 1320 Firmware, Furunosystems Acera 1320, Furunosystems Acera 1210 Firmware.