CVE-2023-35194
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability is specifically for the `system` call in the file `/web/MANGA/cgi-bin/api.cgi` for firmware version 6.3.5 at offset `0x4bde44`.
Affected (1)
Products: Peplink: Surf Soho Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.3.5 |
| Running on/with | Platform Versions |
|---|---|
Peplink Surf Soho | Version hw1 |
References (3)
Source: talos-cna@cisco.com
ExploitProductThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitProductThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.