HIGH
CVE-2023-49897
CVSS
8.8
KEV
Description
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Summary dbcve.org
OS command injection vulnerability in AE1021PE and AE1021 firmware versions 2.0.9 and earlier allows authenticated attackers to execute arbitrary OS commands due to improper input sanitization when handling user-provided data in system shell calls.
Mitigation
Update firmware to a version newer than 2.0.9 when available; if no patch exists, minimize exposure by restricting network access to the device management interface and limiting privileged accounts.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
50.45%
Probability of exploitation in next 30 days
98.9th percentile
References
https://jvn.jp/en/vu/JVNVU92152057/
Third Party Advisory
https://www.akamai.com/blog/security-research/zero-day-vulnerability-spreading-mirai-patched
Exploit, Third Party Advisory
https://www.cisa.gov/news-events/ics-advisories/icsa-23-355-01
Third Party Advisory, US Government Resource
https://www.fxc.jp/news/20231206
Release Notes, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-49897
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.