PT-2023-21690 · Unknown · Wi-Fi Ap Unit Ac-Pd-Wapu+2
Chuya Hayakawa
·
Published
2023-05-23
·
Updated
2025-01-17
·
CVE-2023-28392
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wi-Fi AP UNIT AC-PD-WAPU versions 1.05 B04 and earlier
Wi-Fi AP UNIT AC-PD-WAPUM versions 1.05 B04 and earlier
Wi-Fi AP UNIT AC-PD-WAPU-P versions 1.05 B04P and earlier
Wi-Fi AP UNIT AC-PD-WAPUM-P versions 1.05 B04P and earlier
AC-WAPU-300 versions 1.00 B07 and earlier
AC-WAPU-300-P versions 1.00 B08P and earlier
AC-WAPUM-300 versions 1.00 B07 and earlier
AC-WAPUM-300-P versions 1.00 B08P and earlier
Description
The issue allows an authenticated user with administrative privilege to execute an arbitrary OS command. This can be exploited by a remote authenticated attacker.
Recommendations
For Wi-Fi AP UNIT AC-PD-WAPU versions 1.05 B04 and earlier, update to a version later than 1.05 B04.
For Wi-Fi AP UNIT AC-PD-WAPUM versions 1.05 B04 and earlier, update to a version later than 1.05 B04.
For Wi-Fi AP UNIT AC-PD-WAPU-P versions 1.05 B04P and earlier, update to a version later than 1.05 B04P.
For Wi-Fi AP UNIT AC-PD-WAPUM-P versions 1.05 B04P and earlier, update to a version later than 1.05 B04P.
For AC-WAPU-300 versions 1.00 B07 and earlier, update to a version later than 1.00 B07.
For AC-WAPU-300-P versions 1.00 B08P and earlier, update to a version later than 1.00 B08P.
For AC-WAPUM-300 versions 1.00 B07 and earlier, update to a version later than 1.00 B07.
For AC-WAPUM-300-P versions 1.00 B08P and earlier, update to a version later than 1.00 B08P.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ac-Wapu-300
Ac-Wapu-300-P
Wi-Fi Ap Unit Ac-Pd-Wapu