← Back

CVE-2023-20820

nvd nist
Published: Sep 4, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

In wlan service, there is a possible command injection due to improper input validation. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00244189; Issue ID: WCNCR00244189.

Affected (2)

Products: Openwrt: Openwrt
1 product
Openwrt
Configuration A
2 vulnerable · 13 platform
Vulnerable SoftwareAffected Versions
Openwrt
Version 19.07.0
Version 21.02.0
Running on/withPlatform Versions
Mediatek
Mt6890
All versions
Mediatek
Mt7603
All versions
Mediatek
Mt7612
All versions
Mediatek
Mt7613
All versions
Mediatek
Mt7615
All versions
Mediatek
Mt7622
All versions
Mediatek
Mt7626
All versions
Mediatek
Mt7629
All versions
Mediatek
Mt7915
All versions
Mediatek
Mt7916
All versions
Mediatek
Mt7981
All versions
Mediatek
Mt7986
All versions
Mediatek
Mt7990
All versions

References (2)

Source: security@mediatek.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.