CVE-2023-0862
The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file uploads and deletion.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file uploads and deletion. By uploading malicious files to the web root directory, authenticated users could gain remote command execution with elevated privileges. This issue affects NSRW: from 4.3.0.0 before 4.3.0.119, from 4.4.0.0 before 4.4.0.118, from 4.6.0.0 before 4.6.0.105, from 4.7.0.0 before 4.7.0.103.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.35% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- netmodule/netmodule router software
- Source
- research@onekey.com
References
- https://onekey.com/blog/security-advisory-netmodule-multiple-vulnerabilities/Third Party Advisory
- https://share.netmodule.com/public/system-software/4.7/4.7.0.103/NRSW-RN-4.7.0.103.pdfRelease Notes, Vendor Advisory
- https://onekey.com/blog/security-advisory-netmodule-multiple-vulnerabilities/Third Party Advisory
- https://share.netmodule.com/public/system-software/4.7/4.7.0.103/NRSW-RN-4.7.0.103.pdfRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.