9.1
CVSSv3

CVE-2023-39367

Published: 17/04/2024 Updated: 17/04/2024
CVSS v3 Base Score: 9.1 | Impact Score: 6 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Vendor Advisories

Check Point Reference: CPAI-2023-1703 Date Published: 27 May 2024 Severity: Critical ...