Command Injection Vulnerability in MitraStar GPT-2741GNAC Router
CVE-2023-33381
Key Information:
- Vendor
Mitrastar
- Status
- Vendor
- CVE Published:
- 6 June 2023
Badges
What is CVE-2023-33381?
A command injection flaw affects the ping functionality of the MitraStar GPT-2741GNAC router, allowing an authenticated user to execute arbitrary operating system commands. By sending specifically crafted input through the router's ping feature, attackers could manipulate the router's command processing, posing serious security risks. It is essential for users of the GPT-2741GNAC to take precautions and apply necessary updates to mitigate possible threats.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
56% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability Reserved