VulnerabilityModified
CVE-2023-39367
An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU).
HIGH 7.2EPSS 37.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 37.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 37.68% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- peplink/smart reader firmware
- Source
- talos-cna@cisco.com
References
- https://forum.peplink.com/t/peplink-security-advisory-smart-reader-firmware-1-2-0-cve-2023-43491-cve-2023-45209-cve-2023-39367-cve-2023-45744-cve-2023-40146/47256Vendor Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2023-1867Exploit, Third Party Advisory
- https://forum.peplink.com/t/peplink-security-advisory-smart-reader-firmware-1-2-0-cve-2023-43491-cve-2023-45209-cve-2023-39367-cve-2023-45744-cve-2023-40146/47256Vendor Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2023-1867Exploit, Third Party Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1867
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.