PT-2023-1546 · Delta Electronics · Dx-2100-L1-Cn

T. Weber

·

Published

2023-02-02

·

Updated

2025-01-17

·

CVE-2023-0432

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Delta Electronics DX-2100-L1-CN (affected versions not specified)
Description The web configuration service of the affected device contains an authenticated command injection vulnerability. It can be used to execute system commands on the operating system (OS) from the device in the context of the user "root." If the attacker has credentials for the web service, then the device could be fully compromised.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-00997
CVE-2023-0432

Affected Products

Dx-2100-L1-Cn