PT-2023-8559 · Baicells · Baicells Nova 436Q+2

Rustam Amin

·

Publicado

2023-02-10

·

Atualizado

2023-02-14

·

CVE-2023-0776

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7
Description The issue is related to the exploitation of Baicells devices via HTTP command injections, allowing remote shell code execution with root permissions. This is possible due to the lack of protection measures for the web page structure. Commands are executed using pre-login execution. A third-party analyst has tested and validated the exploitability of this issue.
Recommendations For Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7, consider disabling HTTP command execution until a patch is available. Restrict access to the web interface to minimize the risk of exploitation. Avoid using pre-login execution for commands until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-01166
CVE-2023-0776

Produtos afetados

Baicells Neutrino 430 Lte Tdd Enodeb
Baicells Nova 430E
Baicells Nova 436Q