Vulnerability Description
Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows authenticated remote attackers to execute commands as root via specially crafted HTTP requests to the vulnerable endpoint.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juplink | Rx4-1500 Firmware | 1.0.2 |
| Juplink | Rx4-1500 | - |
Related Weaknesses (CWE)
References
- https://blog.exodusintel.com/2023/09/18/juplink-rx4-1500-command-injection-vulneThird Party Advisory
- https://blog.exodusintel.com/2023/09/18/juplink-rx4-1500-command-injection-vulneThird Party Advisory
FAQ
What is CVE-2023-41029?
CVE-2023-41029 is a vulnerability with a CVSS score of 8.0 (HIGH). Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows authenticated remote attackers to execute comman...
How severe is CVE-2023-41029?
CVE-2023-41029 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-41029?
Check the references section above for vendor advisories and patch information. Affected products include: Juplink Rx4-1500 Firmware, Juplink Rx4-1500.