Vulnerability Description
Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authenticated attackers to execute commands via specially crafted requests to the vulnerable endpoint.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juplink | Rx4-1500 Firmware | 1.0.2 |
| Juplink | Rx4-1500 | - |
Related Weaknesses (CWE)
References
- https://blog.exodusintel.com/2023/09/18/juplink-rx4-1500-homemng-command-injectiThird Party Advisory
- https://blog.exodusintel.com/2023/09/18/juplink-rx4-1500-homemng-command-injectiThird Party Advisory
FAQ
What is CVE-2023-41031?
CVE-2023-41031 is a vulnerability with a CVSS score of 8.0 (HIGH). Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authenticated attackers to execute commands via specially crafted requests to the vulnera...
How severe is CVE-2023-41031?
CVE-2023-41031 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-41031?
Check the references section above for vendor advisories and patch information. Affected products include: Juplink Rx4-1500 Firmware, Juplink Rx4-1500.