8.8
CVSSv3

CVE-2023-28381

Published: 11/10/2023 Updated: 18/10/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An OS command injection vulnerability exists in the admin.cgi MVPN_trial_init functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

peplink surf_soho_firmware 6.3.5