OS Command Injection Vulnerability in Peplink Surf SOHO Router
CVE-2023-27380
7.2HIGH
What is CVE-2023-27380?
A serious OS command injection vulnerability has been identified in the USSD_send functionality of the Peplink Surf SOHO HW1 v6.3.5. By sending a specially crafted HTTP request, an attacker with valid authentication can execute arbitrary commands on the device. This could potentially allow unauthorized access to system functionalities, making robust network defenses crucial for users of this product. It’s vital for organizations to evaluate their exposure to this vulnerability and implement necessary security measures.
Affected Version(s)
Surf SOHO HW1 v6.3.5 (in QEMU)
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Matt Wiseman of Cisco Talos.
